mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
smb: client: Fix use-after-free in cifs_try_adding_channels()
cifs_try_adding_channels() takes a temporary reference to an interface
before dropping iface_lock. If cifs_ses_add_channel() fails, it drops
that reference and then increments iface->weight_fulfilled.
A concurrent interface list refresh can remove the list reference while
channel creation is in progress. In that case, the failure-path
kref_put() releases the last reference and frees iface. Updating
weight_fulfilled afterward then accesses freed memory.
Increment weight_fulfilled before dropping the temporary reference,
keeping iface alive for the final access.
Fixes: 6aac002bcf ("cifs: failure to add channel on iface should bump up weight")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
This commit is contained in:
parent
c422d34a4a
commit
4986410316
|
|
@ -233,9 +233,9 @@ int cifs_try_adding_channels(struct cifs_ses *ses)
|
|||
cifs_dbg(VFS, "failed to open extra channel on iface:%pIS rc=%d\n",
|
||||
&iface->sockaddr,
|
||||
rc);
|
||||
kref_put(&iface->refcount, release_iface);
|
||||
/* failure to add chan should increase weight */
|
||||
iface->weight_fulfilled++;
|
||||
kref_put(&iface->refcount, release_iface);
|
||||
continue;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user