smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()

See the procedure below:

  ksmbd_tree_conn_connect
    ksmbd_share_config_get
      share->name = kstrdup() // fail
      if (!test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) // false
      // do not check `share->name`
    ksmbd_ipc_tree_connect_request
      strlen(share->name) // null-ptr-deref

Fixes: e2f34481b2 ("cifsd: add server-side procedures for SMB3")
Signed-off-by: ZhangGuoDong <zhangguodong@kylinos.cn>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
ZhangGuoDong 2026-07-31 11:50:03 +00:00 committed by Namjae Jeon
parent 6eac877e0e
commit d2ccf905f4

View File

@ -215,6 +215,11 @@ static struct ksmbd_share_config *share_config_request(struct ksmbd_work *work,
ksmbd_share_tree_conn_init(share);
INIT_LIST_HEAD(&share->veto_list);
share->name = kstrdup(name, KSMBD_DEFAULT_GFP);
if (!share->name) {
kill_share(share);
share = NULL;
goto out;
}
if (!test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) {
int path_len = PATH_MAX;
@ -260,7 +265,7 @@ static struct ksmbd_share_config *share_config_request(struct ksmbd_work *work,
share->path = NULL;
}
}
if (ret || !share->name) {
if (ret) {
kill_share(share);
share = NULL;
goto out;