* [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
2026-06-23 2:12 [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions liuqiangneo
@ 2026-06-23 2:12 ` liuqiangneo
2026-06-23 2:28 ` ChenXiaoSong
2026-06-23 2:12 ` [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr liuqiangneo
2026-06-23 2:12 ` [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr liuqiangneo
2 siblings, 1 reply; 7+ messages in thread
From: liuqiangneo @ 2026-06-23 2:12 UTC (permalink / raw)
To: linkinjeon, smfrench, chenxiaosong, senozhatsky, tom
Cc: linux-cifs, linux-kernel, liuqiangneo, Qiang Liu
From: Qiang Liu <liuqiang@kylinos.cn>
Move kfree(sd_ndr.data) into the out cleanup path to avoid memory
leak on error.
Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
---
fs/smb/server/vfs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 74b0307cb100..febe9f7b54c3 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1479,8 +1479,8 @@ int ksmbd_vfs_set_sd_xattr(struct ksmbd_conn *conn,
if (rc < 0)
pr_err("Failed to store XATTR ntacl :%d\n", rc);
- kfree(sd_ndr.data);
out:
+ kfree(sd_ndr.data);
kfree(acl_ndr.data);
kfree(smb_acl);
kfree(def_smb_acl);
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread* Re: [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
2026-06-23 2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
@ 2026-06-23 2:28 ` ChenXiaoSong
0 siblings, 0 replies; 7+ messages in thread
From: ChenXiaoSong @ 2026-06-23 2:28 UTC (permalink / raw)
To: liuqiangneo, linkinjeon, smfrench, senozhatsky, tom
Cc: linux-cifs, linux-kernel, Qiang Liu
Looks good. Feel free to add:
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
On 6/23/26 10:12, liuqiangneo@163.com wrote:
> From: Qiang Liu <liuqiang@kylinos.cn>
>
> Move kfree(sd_ndr.data) into the out cleanup path to avoid memory
> leak on error.
>
> Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
> ---
> fs/smb/server/vfs.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
> index 74b0307cb100..febe9f7b54c3 100644
> --- a/fs/smb/server/vfs.c
> +++ b/fs/smb/server/vfs.c
> @@ -1479,8 +1479,8 @@ int ksmbd_vfs_set_sd_xattr(struct ksmbd_conn *conn,
> if (rc < 0)
> pr_err("Failed to store XATTR ntacl :%d\n", rc);
>
> - kfree(sd_ndr.data);
> out:
> + kfree(sd_ndr.data);
> kfree(acl_ndr.data);
> kfree(smb_acl);
> kfree(def_smb_acl);
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr
2026-06-23 2:12 [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions liuqiangneo
2026-06-23 2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
@ 2026-06-23 2:12 ` liuqiangneo
2026-06-23 2:44 ` ChenXiaoSong
2026-06-23 2:12 ` [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr liuqiangneo
2 siblings, 1 reply; 7+ messages in thread
From: liuqiangneo @ 2026-06-23 2:12 UTC (permalink / raw)
To: linkinjeon, smfrench, chenxiaosong, senozhatsky, tom
Cc: linux-cifs, linux-kernel, liuqiangneo, Qiang Liu
From: Qiang Liu <liuqiang@kylinos.cn>
Zero-initialize xattr_ntacl struct and reorder error cleanup labels
to ensure acl.sd_buf is released on all error paths.
Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
---
fs/smb/server/vfs.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index febe9f7b54c3..60b4210d5ab8 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1496,7 +1496,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
struct ndr n;
struct inode *inode = d_inode(dentry);
struct ndr acl_ndr = {0};
- struct xattr_ntacl acl;
+ struct xattr_ntacl acl = {0};
struct xattr_smb_acl *smb_acl = NULL, *def_smb_acl = NULL;
__u8 cmp_hash[XATTR_SD_HASH_SIZE] = {0};
@@ -1533,6 +1533,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
*pntsd = acl.sd_buf;
if (acl.sd_size < sizeof(struct smb_ntsd)) {
pr_err("sd size is invalid\n");
+ rc = -EINVAL;
goto out_free;
}
@@ -1548,12 +1549,12 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
kfree(acl_ndr.data);
kfree(smb_acl);
kfree(def_smb_acl);
+
+free_n_data:
if (rc < 0) {
kfree(acl.sd_buf);
*pntsd = NULL;
}
-
-free_n_data:
kfree(n.data);
return rc;
}
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread* [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr
2026-06-23 2:12 [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions liuqiangneo
2026-06-23 2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
2026-06-23 2:12 ` [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr liuqiangneo
@ 2026-06-23 2:12 ` liuqiangneo
2026-06-23 2:46 ` ChenXiaoSong
2 siblings, 1 reply; 7+ messages in thread
From: liuqiangneo @ 2026-06-23 2:12 UTC (permalink / raw)
To: linkinjeon, smfrench, chenxiaosong, senozhatsky, tom
Cc: linux-cifs, linux-kernel, liuqiangneo, Qiang Liu
From: Qiang Liu <liuqiang@kylinos.cn>
Free ndr buffer data when ndr_encode_dos_attr() returns error
to avoid memory leak.
Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
---
fs/smb/server/vfs.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 60b4210d5ab8..18d5412081de 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1568,8 +1568,10 @@ int ksmbd_vfs_set_dos_attrib_xattr(struct mnt_idmap *idmap,
int err;
err = ndr_encode_dos_attr(&n, da);
- if (err)
+ if (err) {
+ kfree(n.data);
return err;
+ }
err = ksmbd_vfs_setxattr(idmap, path, XATTR_NAME_DOS_ATTRIBUTE,
(void *)n.data, n.offset, 0, get_write);
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread* Re: [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr
2026-06-23 2:12 ` [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr liuqiangneo
@ 2026-06-23 2:46 ` ChenXiaoSong
0 siblings, 0 replies; 7+ messages in thread
From: ChenXiaoSong @ 2026-06-23 2:46 UTC (permalink / raw)
To: liuqiangneo, linkinjeon, smfrench, senozhatsky, tom
Cc: linux-cifs, linux-kernel, Qiang Liu
We can add a label and use `goto` to free n.data
On 6/23/26 10:12, liuqiangneo@163.com wrote:
> From: Qiang Liu <liuqiang@kylinos.cn>
>
> Free ndr buffer data when ndr_encode_dos_attr() returns error
> to avoid memory leak.
>
> Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
> ---
> fs/smb/server/vfs.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
> index 60b4210d5ab8..18d5412081de 100644
> --- a/fs/smb/server/vfs.c
> +++ b/fs/smb/server/vfs.c
> @@ -1568,8 +1568,10 @@ int ksmbd_vfs_set_dos_attrib_xattr(struct mnt_idmap *idmap,
> int err;
>
> err = ndr_encode_dos_attr(&n, da);
> - if (err)
> + if (err) {
> + kfree(n.data);
> return err;
> + }
>
> err = ksmbd_vfs_setxattr(idmap, path, XATTR_NAME_DOS_ATTRIBUTE,
> (void *)n.data, n.offset, 0, get_write);
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
^ permalink raw reply [flat|nested] 7+ messages in thread