mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] smb: client: avoid NULL resp_iov dereference
@ 2026-09-26 13:22 Zihan Xi
  2026-09-27  2:23 ` Namjae Jeon
  2026-09-27 14:54 ` Dan Carpenter
  0 siblings, 2 replies; 6+ messages in thread
From: Zihan Xi @ 2026-09-26 13:22 UTC (permalink / raw)
  To: pc, linkinjeon
  Cc: zihanx, ronniesahlberg, sprasad, tom, bharathsm, dhowells,
	stfrench, linux-cifs, samba-technical, linux-kernel, stable,
	kernel test robot, Dan Carpenter, Luxing Yin

compound_send_recv() only populates response vectors when resp_iov is
non-NULL. The final pre-authentication hash update nevertheless
dereferences resp_iov[0] whenever all compound requests complete.

Guard the update with resp_iov to match the response-buffer handling and
avoid a NULL pointer dereference on callers that do not request response
vectors.

Fixes: 62432a3f5145 ("cifs: Clean up some places where an extra kvec[] was required for rfc1002")
Cc: stable@vger.kernel.org
Reported-by: kernel test robot <lkp@intel.com>
Reported-by: Dan Carpenter <error27@gmail.com>
Closes: https://lore.kernel.org/all/202609241449.HlHmnZFZ-lkp@intel.com/
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
---
 fs/smb/client/transport.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/smb/client/transport.c b/fs/smb/client/transport.c
index 6e21b5f8754a1..307bd82128781 100644
--- a/fs/smb/client/transport.c
+++ b/fs/smb/client/transport.c
@@ -1111,7 +1111,7 @@ compound_send_recv(const unsigned int xid, struct cifs_ses *ses,
 	/*
 	 * Compounding is never used during session establish.
 	 */
-	if (num_processed == num_rqst) {
+	if (num_processed == num_rqst && resp_iov) {
 		spin_lock(&ses->ses_lock);
 		if ((ses->ses_status == SES_NEW) || (optype & CIFS_NEG_OP) || (optype & CIFS_SESS_OP)) {
 			struct kvec iov = {
-- 
2.43.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] smb: client: avoid NULL resp_iov dereference
  2026-09-26 13:22 [PATCH] smb: client: avoid NULL resp_iov dereference Zihan Xi
@ 2026-09-27  2:23 ` Namjae Jeon
  2026-09-27  4:22   ` zihan xi
  2026-09-27 14:54 ` Dan Carpenter
  1 sibling, 1 reply; 6+ messages in thread
From: Namjae Jeon @ 2026-09-27  2:23 UTC (permalink / raw)
  To: Zihan Xi
  Cc: pc, ronniesahlberg, sprasad, tom, bharathsm, dhowells, stfrench,
	linux-cifs, samba-technical, linux-kernel, stable,
	kernel test robot, Dan Carpenter, Luxing Yin

> @@ -1111,7 +1111,7 @@ compound_send_recv(const unsigned int xid, struct cifs_ses *ses,
>         /*
>          * Compounding is never used during session establish.
>          */
> -       if (num_processed == num_rqst) {
> +       if (num_processed == num_rqst && resp_iov) {
Could you please explain how this code path can be reached? Earlier in
the function, if ses->ses_status == SES_NEW or optype contains
CIFS_NEG_OP or CIFS_SESS_OP, the code checks !resp_iov and returns
-EINVAL.

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] smb: client: avoid NULL resp_iov dereference
  2026-09-27  2:23 ` Namjae Jeon
@ 2026-09-27  4:22   ` zihan xi
  0 siblings, 0 replies; 6+ messages in thread
From: zihan xi @ 2026-09-27  4:22 UTC (permalink / raw)
  To: Namjae Jeon
  Cc: pc, ronniesahlberg, sprasad, tom, bharathsm, dhowells, stfrench,
	linux-cifs, samba-technical, linux-kernel, stable,
	kernel test robot, Dan Carpenter, Luxing Yin

On Sun, Sep 27, 2026 at 10:23 AM Namjae Jeon <linkinjeon@kernel.org> wrote:
>
> > @@ -1111,7 +1111,7 @@ compound_send_recv(const unsigned int xid, struct cifs_ses *ses,
> >         /*
> >          * Compounding is never used during session establish.
> >          */
> > -       if (num_processed == num_rqst) {
> > +       if (num_processed == num_rqst && resp_iov) {
> Could you please explain how this code path can be reached? Earlier in
> the function, if ses->ses_status == SES_NEW or optype contains
> CIFS_NEG_OP or CIFS_SESS_OP, the code checks !resp_iov and returns
> -EINVAL.

Hi Namjae,

Thanks for checking.

You are right. I could not find a reachable path to the
resp_iov[0] dereference with resp_iov == NULL.

Before waiting for responses, the session-establishment branch
returns -EINVAL when resp_iov is NULL. For ordinary requests that
may use a NULL resp_iov, optype is fixed and does not contain
CIFS_NEG_OP or CIFS_SESS_OP. In addition, SES_NEW is only the
initial session state and is not re-entered during this operation.

Therefore, the condition surrounding the resp_iov[0] dereference
cannot become true with resp_iov == NULL. The smatch warning does not
account for this control-flow and state invariant.

The added guard is redundant, so I will withdraw this follow-up
patch.

Thanks,
Zihan

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] smb: client: avoid NULL resp_iov dereference
  2026-09-26 13:22 [PATCH] smb: client: avoid NULL resp_iov dereference Zihan Xi
  2026-09-27  2:23 ` Namjae Jeon
@ 2026-09-27 14:54 ` Dan Carpenter
  2026-09-28  5:42   ` Philip Li
  1 sibling, 1 reply; 6+ messages in thread
From: Dan Carpenter @ 2026-09-27 14:54 UTC (permalink / raw)
  To: Zihan Xi
  Cc: pc, linkinjeon, ronniesahlberg, sprasad, tom, bharathsm,
	dhowells, stfrench, linux-cifs, samba-technical, linux-kernel,
	stable, kernel test robot, Luxing Yin

On Sat, Sep 26, 2026 at 01:22:08PM +0000, Zihan Xi wrote:
> compound_send_recv() only populates response vectors when resp_iov is
> non-NULL. The final pre-authentication hash update nevertheless
> dereferences resp_iov[0] whenever all compound requests complete.
> 
> Guard the update with resp_iov to match the response-buffer handling and
> avoid a NULL pointer dereference on callers that do not request response
> vectors.
> 
> Fixes: 62432a3f5145 ("cifs: Clean up some places where an extra kvec[] was required for rfc1002")
> Cc: stable@vger.kernel.org
> Reported-by: kernel test robot <lkp@intel.com>
> Reported-by: Dan Carpenter <error27@gmail.com>
> Closes: https://lore.kernel.org/all/202609241449.HlHmnZFZ-lkp@intel.com/

Originally the idea was that I would review these and filter out
the false positives, but these days people use lei to read email so
they recieve the unfiltered warnings.  The zero day bot should
probably put a "Unfiltered warning" note at the top to let people
know the warning hasn't been reviewed.

regards,
dan carpenter



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] smb: client: avoid NULL resp_iov dereference
  2026-09-27 14:54 ` Dan Carpenter
@ 2026-09-28  5:42   ` Philip Li
  2026-09-28  6:57     ` Dan Carpenter
  0 siblings, 1 reply; 6+ messages in thread
From: Philip Li @ 2026-09-28  5:42 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: Zihan Xi, pc, linkinjeon, ronniesahlberg, sprasad, tom,
	bharathsm, dhowells, stfrench, linux-cifs, samba-technical,
	linux-kernel, stable, kernel test robot, Luxing Yin

On Sun, Sep 27, 2026 at 05:54:30PM +0300, Dan Carpenter wrote:
> On Sat, Sep 26, 2026 at 01:22:08PM +0000, Zihan Xi wrote:
> > compound_send_recv() only populates response vectors when resp_iov is
> > non-NULL. The final pre-authentication hash update nevertheless
> > dereferences resp_iov[0] whenever all compound requests complete.
> > 
> > Guard the update with resp_iov to match the response-buffer handling and
> > avoid a NULL pointer dereference on callers that do not request response
> > vectors.
> > 
> > Fixes: 62432a3f5145 ("cifs: Clean up some places where an extra kvec[] was required for rfc1002")
> > Cc: stable@vger.kernel.org
> > Reported-by: kernel test robot <lkp@intel.com>
> > Reported-by: Dan Carpenter <error27@gmail.com>
> > Closes: https://lore.kernel.org/all/202609241449.HlHmnZFZ-lkp@intel.com/
> 
> Originally the idea was that I would review these and filter out
> the false positives, but these days people use lei to read email so
> they recieve the unfiltered warnings.  The zero day bot should
> probably put a "Unfiltered warning" note at the top to let people
> know the warning hasn't been reviewed.

Got it, I will add this note to the bot report for unfiltered warnings.

Thanks

> 
> regards,
> dan carpenter
> 
> 
> 

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] smb: client: avoid NULL resp_iov dereference
  2026-09-28  5:42   ` Philip Li
@ 2026-09-28  6:57     ` Dan Carpenter
  0 siblings, 0 replies; 6+ messages in thread
From: Dan Carpenter @ 2026-09-28  6:57 UTC (permalink / raw)
  To: Philip Li
  Cc: Zihan Xi, pc, linkinjeon, ronniesahlberg, sprasad, tom,
	bharathsm, dhowells, stfrench, linux-cifs, samba-technical,
	linux-kernel, stable, kernel test robot, Luxing Yin

On Mon, Sep 28, 2026 at 01:42:40PM +0800, Philip Li wrote:
> On Sun, Sep 27, 2026 at 05:54:30PM +0300, Dan Carpenter wrote:
> > On Sat, Sep 26, 2026 at 01:22:08PM +0000, Zihan Xi wrote:
> > > compound_send_recv() only populates response vectors when resp_iov is
> > > non-NULL. The final pre-authentication hash update nevertheless
> > > dereferences resp_iov[0] whenever all compound requests complete.
> > > 
> > > Guard the update with resp_iov to match the response-buffer handling and
> > > avoid a NULL pointer dereference on callers that do not request response
> > > vectors.
> > > 
> > > Fixes: 62432a3f5145 ("cifs: Clean up some places where an extra kvec[] was required for rfc1002")
> > > Cc: stable@vger.kernel.org
> > > Reported-by: kernel test robot <lkp@intel.com>
> > > Reported-by: Dan Carpenter <error27@gmail.com>
> > > Closes: https://lore.kernel.org/all/202609241449.HlHmnZFZ-lkp@intel.com/
> > 
> > Originally the idea was that I would review these and filter out
> > the false positives, but these days people use lei to read email so
> > they recieve the unfiltered warnings.  The zero day bot should
> > probably put a "Unfiltered warning" note at the top to let people
> > know the warning hasn't been reviewed.
> 
> Got it, I will add this note to the bot report for unfiltered warnings.
> 

Thanks, Philip!

regards,
dan carpenter


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-28  6:57 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-26 13:22 [PATCH] smb: client: avoid NULL resp_iov dereference Zihan Xi
2026-09-27  2:23 ` Namjae Jeon
2026-09-27  4:22   ` zihan xi
2026-09-27 14:54 ` Dan Carpenter
2026-09-28  5:42   ` Philip Li
2026-09-28  6:57     ` Dan Carpenter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®