mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 18:21:24 +02:00
ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling
1. When ndr_decode_v4_ntacl() fails, the code jumped to free_n_data which only freed n.data, skipping kfree(acl.sd_buf) and leaking the buffer. Zero-initialize struct xattr_ntacl acl, reorder error labels to out_free to release acl.sd_buf on all error paths. 2. if (acl.sd_size < sizeof(struct smb_ntsd)) is true, original code returned success without freeing sd_buf and left stale *pntsd. Set rc = -EINVAL before jumping to out_free to return error code and free buffer. Signed-off-by: Qiang Liu <liuqiang@kylinos.cn> Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn> Acked-by: Namjae Jeon <linkinjeon@kernel.org> Signed-off-by: Steve French <stfrench@microsoft.com>
This commit is contained in:
parent
d4d56b00c7
commit
d708a36634
|
|
@ -1504,7 +1504,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
|
|||
struct ndr n;
|
||||
struct inode *inode = d_inode(dentry);
|
||||
struct ndr acl_ndr = {0};
|
||||
struct xattr_ntacl acl;
|
||||
struct xattr_ntacl acl = {0};
|
||||
struct xattr_smb_acl *smb_acl = NULL, *def_smb_acl = NULL;
|
||||
__u8 cmp_hash[XATTR_SD_HASH_SIZE] = {0};
|
||||
|
||||
|
|
@ -1515,7 +1515,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
|
|||
n.length = rc;
|
||||
rc = ndr_decode_v4_ntacl(&n, &acl);
|
||||
if (rc)
|
||||
goto free_n_data;
|
||||
goto out_free;
|
||||
|
||||
smb_acl = ksmbd_vfs_make_xattr_posix_acl(idmap, inode,
|
||||
ACL_TYPE_ACCESS);
|
||||
|
|
@ -1541,6 +1541,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
|
|||
*pntsd = acl.sd_buf;
|
||||
if (acl.sd_size < sizeof(struct smb_ntsd)) {
|
||||
pr_err("sd size is invalid\n");
|
||||
rc = -EINVAL;
|
||||
goto out_free;
|
||||
}
|
||||
|
||||
|
|
@ -1560,8 +1561,6 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
|
|||
kfree(acl.sd_buf);
|
||||
*pntsd = NULL;
|
||||
}
|
||||
|
||||
free_n_data:
|
||||
kfree(n.data);
|
||||
return rc;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user