All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paulo Alcantara <pc@manguebit.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-kernel@vger.kernel.org, linux-cifs@vger.kernel.org
Subject: [GIT PULL] smb client fixes for 7.3-rc3
Date: Thu, 10 Sep 2026 12:45:41 -0300	[thread overview]
Message-ID: <bb769b6f6f976d75cbfca3ed00556bde@manguebit.org> (raw)

Linus,

Please consider pulling these smb client fixes for v7.3-rc3. They
address file type corruption in reparse point handling, uid/gid
ownership mapping bugs, heap overflows in DACL rewriting, reference
count leaks, a DFS use-after-free and hardening of legacy smb1 input
validation. All fixes are for stable.

Thanks,
Paulo

----------------------------------------------------------------
The following changes since commit 89a312991dc6e638a36adc43ccb91dbc25504c04:

  Merge tag 'cifs-fixes-7.3-rc2' of https://git.manguebit.org/linux (2026-09-01 13:37:14 -0700)

are available in the Git repository at:

  https://git.manguebit.org/linux.git tags/cifs-fixes-7.3-rc3

for you to fetch changes up to cb26524ef4ac28fcfa554c0656e8dc412c38a8ff:

  smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (2026-09-09 22:06:05 -0300)

----------------------------------------------------------------
smb client fixes for v7.3-rc3

A batch of bug fixes for the smb client:

 - File type corruption fixes in reparse point handling: setting S_IFMT
   bits without clearing the existing type first corrupted the file mode
   (e.g. S_IFREG | S_IFCHR == S_IFLNK). Fixed in the WSL, POSIX and
   native symlink reparse parsers. Also fixes an uninitialized SID
   structure in the POSIX readdir path when parsing fails.

 - Ownership mapping fixes: forceuid/forcegid mount options were
   ignored in several code paths (SID-to-id mapping, WSL extended
   attributes, POSIX extensions getattr), allowing an untrusted server
   to dictate local file ownership despite explicit mount overrides.

 - Heap overflow and overflow fixes in DACL rewriting: replacing short
   SIDs with long ones could overflow the DACL buffer, and the u16
   accumulator for DACL size could wrap around with enough ACEs.

 - Reference count leak fixes in oplock break and deferred close:
   duplicate oplock breaks on a queued work item leaked a
   cifsFileInfo reference, and deferred close had a similar leak when
   requeueing a running work item. Both cause busy-inode oopses on
   unmount.

 - DFS superblock use-after-free fix: the iterator callback stored a
   raw superblock pointer without pinning it, racing with automount
   expiry.

 - One-byte slab OOB read in the native symlink parser when handling
   share-root relative paths.

 - Hardening of legacy SMB1 input: reject userspace-crafted
   cifs.idmap key descriptions that bypass kernel origin checks, and
   validate DataOffset in CIFSSMBRead() to prevent heap info
   disclosure from a malicious server.

 - DFS cache fix: defer metadata updates until target copying
   succeeds to prevent partial-state cache entries on allocation
   failure.

----------------------------------------------------------------
Aohan Mei (1):
      smb: client: reject userspace cifs.idmap descriptions

Bjoern Doebel (4):
      smb: client: avoid leaking refcount in cifs_queue_oplock_break()
      smb: client: avoid leaking refcount when cifs_sb_tlink() fails
      smb: client: fix heap overflow in DACL owner/group rewrite
      smb: client: fail DACL rewrite when the new DACL exceeds 64K

Diego Oliva (2):
      smb: client: reject short READ responses in CIFSSMBRead()
      smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()

Fan Wu (1):
      smb: client: fix cifsFileInfo reference leak in deferred close

Fredric Cover (1):
      smb: client: fill cache fields after populating cache in copy_ref_data()

Karl Mehltretter (1):
      smb: client: pin DFS superblock in iterator callback

Paulo Alcantara (8):
      smb: client: fix uid/gid override in getattr with posix extensions
      smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid
      smb: client: fix WSL reparse point uid/gid override
      smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
      smb: client: fix file type corruption in wsl_to_fattr()
      smb: client: fix file type corruption in posix_reparse_to_fattr()
      smb: client: fix file type corruption in cifs_reparse_point_to_fattr()
      smb: client: fix one-byte OOB read in smb2_parse_native_symlink()

 fs/smb/client/cifsacl.c   | 95 ++++++++++++++++++++++++++++++++---------------
 fs/smb/client/cifssmb.c   | 26 ++++++++++---
 fs/smb/client/dfs_cache.c | 18 ++++-----
 fs/smb/client/file.c      | 22 ++++++++---
 fs/smb/client/inode.c     | 17 ++++++---
 fs/smb/client/misc.c      | 24 ++++++------
 fs/smb/client/readdir.c   | 17 +++++++--
 fs/smb/client/reparse.c   | 33 ++++++++++------
 fs/smb/client/trace.h     |  1 +
 9 files changed, 172 insertions(+), 81 deletions(-)

             reply	other threads:[~2026-09-10 15:45 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10 15:45 Paulo Alcantara [this message]
2026-09-10 21:52 ` [GIT PULL] smb client fixes for 7.3-rc3 pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bb769b6f6f976d75cbfca3ed00556bde@manguebit.org \
    --to=pc@manguebit.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.