* [GIT PULL] smb client fixes for 7.3-rc3
@ 2026-09-10 15:45 Paulo Alcantara
2026-09-10 21:52 ` pr-tracker-bot
0 siblings, 1 reply; 2+ messages in thread
From: Paulo Alcantara @ 2026-09-10 15:45 UTC (permalink / raw)
To: Linus Torvalds; +Cc: linux-kernel, linux-cifs
Linus,
Please consider pulling these smb client fixes for v7.3-rc3. They
address file type corruption in reparse point handling, uid/gid
ownership mapping bugs, heap overflows in DACL rewriting, reference
count leaks, a DFS use-after-free and hardening of legacy smb1 input
validation. All fixes are for stable.
Thanks,
Paulo
----------------------------------------------------------------
The following changes since commit 89a312991dc6e638a36adc43ccb91dbc25504c04:
Merge tag 'cifs-fixes-7.3-rc2' of https://git.manguebit.org/linux (2026-09-01 13:37:14 -0700)
are available in the Git repository at:
https://git.manguebit.org/linux.git tags/cifs-fixes-7.3-rc3
for you to fetch changes up to cb26524ef4ac28fcfa554c0656e8dc412c38a8ff:
smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (2026-09-09 22:06:05 -0300)
----------------------------------------------------------------
smb client fixes for v7.3-rc3
A batch of bug fixes for the smb client:
- File type corruption fixes in reparse point handling: setting S_IFMT
bits without clearing the existing type first corrupted the file mode
(e.g. S_IFREG | S_IFCHR == S_IFLNK). Fixed in the WSL, POSIX and
native symlink reparse parsers. Also fixes an uninitialized SID
structure in the POSIX readdir path when parsing fails.
- Ownership mapping fixes: forceuid/forcegid mount options were
ignored in several code paths (SID-to-id mapping, WSL extended
attributes, POSIX extensions getattr), allowing an untrusted server
to dictate local file ownership despite explicit mount overrides.
- Heap overflow and overflow fixes in DACL rewriting: replacing short
SIDs with long ones could overflow the DACL buffer, and the u16
accumulator for DACL size could wrap around with enough ACEs.
- Reference count leak fixes in oplock break and deferred close:
duplicate oplock breaks on a queued work item leaked a
cifsFileInfo reference, and deferred close had a similar leak when
requeueing a running work item. Both cause busy-inode oopses on
unmount.
- DFS superblock use-after-free fix: the iterator callback stored a
raw superblock pointer without pinning it, racing with automount
expiry.
- One-byte slab OOB read in the native symlink parser when handling
share-root relative paths.
- Hardening of legacy SMB1 input: reject userspace-crafted
cifs.idmap key descriptions that bypass kernel origin checks, and
validate DataOffset in CIFSSMBRead() to prevent heap info
disclosure from a malicious server.
- DFS cache fix: defer metadata updates until target copying
succeeds to prevent partial-state cache entries on allocation
failure.
----------------------------------------------------------------
Aohan Mei (1):
smb: client: reject userspace cifs.idmap descriptions
Bjoern Doebel (4):
smb: client: avoid leaking refcount in cifs_queue_oplock_break()
smb: client: avoid leaking refcount when cifs_sb_tlink() fails
smb: client: fix heap overflow in DACL owner/group rewrite
smb: client: fail DACL rewrite when the new DACL exceeds 64K
Diego Oliva (2):
smb: client: reject short READ responses in CIFSSMBRead()
smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()
Fan Wu (1):
smb: client: fix cifsFileInfo reference leak in deferred close
Fredric Cover (1):
smb: client: fill cache fields after populating cache in copy_ref_data()
Karl Mehltretter (1):
smb: client: pin DFS superblock in iterator callback
Paulo Alcantara (8):
smb: client: fix uid/gid override in getattr with posix extensions
smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid
smb: client: fix WSL reparse point uid/gid override
smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
smb: client: fix file type corruption in wsl_to_fattr()
smb: client: fix file type corruption in posix_reparse_to_fattr()
smb: client: fix file type corruption in cifs_reparse_point_to_fattr()
smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
fs/smb/client/cifsacl.c | 95 ++++++++++++++++++++++++++++++++---------------
fs/smb/client/cifssmb.c | 26 ++++++++++---
fs/smb/client/dfs_cache.c | 18 ++++-----
fs/smb/client/file.c | 22 ++++++++---
fs/smb/client/inode.c | 17 ++++++---
fs/smb/client/misc.c | 24 ++++++------
fs/smb/client/readdir.c | 17 +++++++--
fs/smb/client/reparse.c | 33 ++++++++++------
fs/smb/client/trace.h | 1 +
9 files changed, 172 insertions(+), 81 deletions(-)
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [GIT PULL] smb client fixes for 7.3-rc3
2026-09-10 15:45 [GIT PULL] smb client fixes for 7.3-rc3 Paulo Alcantara
@ 2026-09-10 21:52 ` pr-tracker-bot
0 siblings, 0 replies; 2+ messages in thread
From: pr-tracker-bot @ 2026-09-10 21:52 UTC (permalink / raw)
To: Paulo Alcantara; +Cc: Linus Torvalds, linux-kernel, linux-cifs
The pull request you sent on Thu, 10 Sep 2026 12:45:41 -0300:
> https://git.manguebit.org/linux.git tags/cifs-fixes-7.3-rc3
has been merged into torvalds/linux.git:
https://git.kernel.org/torvalds/c/0a96d0d726cd380423ac38e2c28f538db2940a1d
Thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/prtracker.html
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-10 21:53 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-10 15:45 [GIT PULL] smb client fixes for 7.3-rc3 Paulo Alcantara
2026-09-10 21:52 ` pr-tracker-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®