From: Paulo Alcantara <pc@manguebit.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-kernel@vger.kernel.org, linux-cifs@vger.kernel.org
Subject: [GIT PULL] smb client fixes for 7.3-rc3
Date: Thu, 10 Sep 2026 12:45:41 -0300 [thread overview]
Message-ID: <bb769b6f6f976d75cbfca3ed00556bde@manguebit.org> (raw)
Linus,
Please consider pulling these smb client fixes for v7.3-rc3. They
address file type corruption in reparse point handling, uid/gid
ownership mapping bugs, heap overflows in DACL rewriting, reference
count leaks, a DFS use-after-free and hardening of legacy smb1 input
validation. All fixes are for stable.
Thanks,
Paulo
----------------------------------------------------------------
The following changes since commit 89a312991dc6e638a36adc43ccb91dbc25504c04:
Merge tag 'cifs-fixes-7.3-rc2' of https://git.manguebit.org/linux (2026-09-01 13:37:14 -0700)
are available in the Git repository at:
https://git.manguebit.org/linux.git tags/cifs-fixes-7.3-rc3
for you to fetch changes up to cb26524ef4ac28fcfa554c0656e8dc412c38a8ff:
smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (2026-09-09 22:06:05 -0300)
----------------------------------------------------------------
smb client fixes for v7.3-rc3
A batch of bug fixes for the smb client:
- File type corruption fixes in reparse point handling: setting S_IFMT
bits without clearing the existing type first corrupted the file mode
(e.g. S_IFREG | S_IFCHR == S_IFLNK). Fixed in the WSL, POSIX and
native symlink reparse parsers. Also fixes an uninitialized SID
structure in the POSIX readdir path when parsing fails.
- Ownership mapping fixes: forceuid/forcegid mount options were
ignored in several code paths (SID-to-id mapping, WSL extended
attributes, POSIX extensions getattr), allowing an untrusted server
to dictate local file ownership despite explicit mount overrides.
- Heap overflow and overflow fixes in DACL rewriting: replacing short
SIDs with long ones could overflow the DACL buffer, and the u16
accumulator for DACL size could wrap around with enough ACEs.
- Reference count leak fixes in oplock break and deferred close:
duplicate oplock breaks on a queued work item leaked a
cifsFileInfo reference, and deferred close had a similar leak when
requeueing a running work item. Both cause busy-inode oopses on
unmount.
- DFS superblock use-after-free fix: the iterator callback stored a
raw superblock pointer without pinning it, racing with automount
expiry.
- One-byte slab OOB read in the native symlink parser when handling
share-root relative paths.
- Hardening of legacy SMB1 input: reject userspace-crafted
cifs.idmap key descriptions that bypass kernel origin checks, and
validate DataOffset in CIFSSMBRead() to prevent heap info
disclosure from a malicious server.
- DFS cache fix: defer metadata updates until target copying
succeeds to prevent partial-state cache entries on allocation
failure.
----------------------------------------------------------------
Aohan Mei (1):
smb: client: reject userspace cifs.idmap descriptions
Bjoern Doebel (4):
smb: client: avoid leaking refcount in cifs_queue_oplock_break()
smb: client: avoid leaking refcount when cifs_sb_tlink() fails
smb: client: fix heap overflow in DACL owner/group rewrite
smb: client: fail DACL rewrite when the new DACL exceeds 64K
Diego Oliva (2):
smb: client: reject short READ responses in CIFSSMBRead()
smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()
Fan Wu (1):
smb: client: fix cifsFileInfo reference leak in deferred close
Fredric Cover (1):
smb: client: fill cache fields after populating cache in copy_ref_data()
Karl Mehltretter (1):
smb: client: pin DFS superblock in iterator callback
Paulo Alcantara (8):
smb: client: fix uid/gid override in getattr with posix extensions
smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid
smb: client: fix WSL reparse point uid/gid override
smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
smb: client: fix file type corruption in wsl_to_fattr()
smb: client: fix file type corruption in posix_reparse_to_fattr()
smb: client: fix file type corruption in cifs_reparse_point_to_fattr()
smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
fs/smb/client/cifsacl.c | 95 ++++++++++++++++++++++++++++++++---------------
fs/smb/client/cifssmb.c | 26 ++++++++++---
fs/smb/client/dfs_cache.c | 18 ++++-----
fs/smb/client/file.c | 22 ++++++++---
fs/smb/client/inode.c | 17 ++++++---
fs/smb/client/misc.c | 24 ++++++------
fs/smb/client/readdir.c | 17 +++++++--
fs/smb/client/reparse.c | 33 ++++++++++------
fs/smb/client/trace.h | 1 +
9 files changed, 172 insertions(+), 81 deletions(-)
next reply other threads:[~2026-09-10 15:45 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 15:45 Paulo Alcantara [this message]
2026-09-10 21:52 ` [GIT PULL] smb client fixes for 7.3-rc3 pr-tracker-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bb769b6f6f976d75cbfca3ed00556bde@manguebit.org \
--to=pc@manguebit.org \
--cc=linux-cifs@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.