All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg KH <gregkh@linuxfoundation.org>
To: Wang Zhaolong <wangzhaolong1@huawei.com>
Cc: cve@kernel.org, linux-kernel@vger.kernel.org,
	linux-cve-announce@vger.kernel.org
Subject: Re: CVE-2025-22077: smb: client: Fix netns refcount imbalance causing leaks and use-after-free
Date: Tue, 22 Apr 2025 07:36:12 +0200	[thread overview]
Message-ID: <2025042242-atrophy-huff-6ba6@gregkh> (raw)
In-Reply-To: <b7822cca-5ef5-4e09-bca1-2857aada4741@huawei.com>

On Mon, Apr 21, 2025 at 10:18:25PM +0800, Wang Zhaolong wrote:
> 
> 
> Hi Greg,
> 
> I apologize for the confusion. Let me clarify the situation more directly:
> 
> > > > 
> > > > 1. Commit 4e7f1644f2ac is currently associated with CVE-2025-22077. However, this
> > > > patch was merely attempting to fix issues introduced by commit e9f2517a3e18 ("smb:
> > > > client: fix TCP timers deadlock after rmmod").
> > 
> > Did it not fix those issues?  If not, we can reject that CVE, please let
> > us know.
> 
> Yes, commit 4e7f1644f2ac did attempt to fix the issues introduced by
> e9f2517a3e18, but it only fixed part of the issues introduced by e9f2517a3e18.
> 
> > 
> > > > 2. As I've previously discussed with Greg Kroah-Hartman on the kernel mailing list[1],
> > > >      commit e9f2517a3e18 (which was intended to address CVE-2024-54680):
> > > >      - Failed to address the actual null pointer dereference in lockdep
> > > >      - Introduced multiple serious issues:
> > > >        - Socket leak vulnerability (bugzilla #219972)
> > > >        - Network namespace refcount imbalance (bugzilla #219792)
> > 
> > So this commit did not actually do anything?  If so, we can reject this
> > CVE.
> > 
> 
> e9f2517a3e18 did not fix any issues and instead introduced a series of problems.
> 
> Here's the actual sequence:
> 
> 1. CVE-2024-53095 vulnerability: Use-after-free of network namespace in
>    SMB client and it's correct fix: ef7134c7fc48 by Kuniyuki Iwashima
> 3. Problematic patch: e9f2517a3e18 (intended for CVE-2024-54680) fixed
>    nothing and introduced new issues while trying to "fix" a non-existent
>    deadlock. ** CVE-2024-54680 has been rejected **
> 4. Attempted fix for some reference count issues: My patch 4e7f1644f2ac
>    (assigned CVE-2025-22077)
> 5. Final resolution: Revert the problematic patch e9f2517a3e18 via commit
>    95d2b9f693ff ("Revert "smb: client: fix TCP timers deadlock after rmmod"").
> 
> What I'm requesting:
> - CVE-2025-22077 should be associated with commit 95d2b9f693ff, which is the actual
>   final fix.

Thank you for explaining it again, this time it made sense :)

The id is now updated, and the data is pushed out to cve.org, thanks!

greg k-h

      reply	other threads:[~2025-04-22  5:36 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-16 14:12 CVE-2025-22077: smb: client: Fix netns refcount imbalance causing leaks and use-after-free Greg Kroah-Hartman
2025-04-21  2:52 ` Wang Zhaolong
2025-04-21  2:59   ` Wang Zhaolong
2025-04-21  6:49     ` Greg KH
2025-04-21 14:18       ` Wang Zhaolong
2025-04-22  5:36         ` Greg KH [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2025042242-atrophy-huff-6ba6@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=wangzhaolong1@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.