From: Greg KH <greg@kroah.com>
To: 朱浩 <zhuhao@stu.pku.edu.cn>
Cc: security <security@kernel.org>,
linkinjeon <linkinjeon@kernel.org>,
linkinjeon <linkinjeon@samba.org>, smfrench <smfrench@gmail.com>,
sfrench <sfrench@samba.org>,
linux-cifs <linux-cifs@vger.kernel.org>
Subject: Re: ksmbd: unlocked iface_list free during server reset vs FSCTL_QUERY_NETWORK_INTERFACE_INFO traversal -> use-after-free (kernel oops)
Date: Wed, 23 Sep 2026 11:22:05 +0200 [thread overview]
Message-ID: <2026092344-muck-retainer-dd6d@gregkh> (raw)
In-Reply-To: <AL*ADQCbK5q8mAaIolsqNaq-.1.1790153264029.Hmail.2401112100@stu.pku.edu.cn>
On Wed, Sep 23, 2026 at 04:47:44PM +0800, 朱浩 wrote:
> Hello,
> I would like to privately report a use-after-free vulnerability in the Linux kernel SMB
> server (ksmbd) that leads to a kernel oops (denial of service). The bug is present in the
> current upstream master as of this writing.
> -------------------------------------------------------------------
> Summary
> -------------------------------------------------------------------
> ksmbd frees the global interface list (iface_list) without any lock during server
> reset / hard-kill, *before* stop_sessions() is invoked. Meanwhile the
> FSCTL_QUERY_NETWORK_INTERFACE_INFO ioctl handler traverses that same list while holding
> only rtnl_lock (a lock the free path does not take), dereferencing freed iface nodes.
> A remote authenticated SMB client that floods FSCTL_QUERY_NETWORK_INTERFACE_INFO while the
> server is being reset can trigger a use-after-free read, producing a KASAN
> slab-use-after-free report and a general protection fault (kernel oops / DoS).
> -------------------------------------------------------------------
> Affected component and versions
> -------------------------------------------------------------------
> Component: Linux kernel, fs/smb/server (ksmbd)
> Confirmed present:
> - Snapshot at commit af5226abb4 (6.15.0-rc3 era), where I reproduced it with KASAN.
That is very very very old and obsolete and known broken and buggy.
Please always test on the latest kernel version, hundreds, if not
thousands, of changes to the ksmbd code have happened since then.
> - Current upstream master (checked 2026-09): ksmbd_tcp_destroy() still frees iface_list
> without any lock, and ksmbd_find_netdev_name_iface_list() still traverses it holding
> only rtnl_lock. No fix is present upstream as far as I can tell.
Please test to verify.
> Suggested fix
> -------------------------------------------------------------------
> Any of:
> 1. Protect iface_list with a dedicated lock shared by ksmbd_tcp_destroy() and
> ksmbd_find_netdev_name_iface_list() (and all other traversers);
> 2. Free the nodes via RCU and traverse under rcu_read_lock();
> 3. Reorder ksmbd_conn_transport_destroy() to run stop_sessions() before freeing iface_list.
Please create a patch that can be applied to resolve the issue so that
you get full credit for this.
thanks,
greg k-h
next prev parent reply other threads:[~2026-09-23 9:32 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 8:47 ksmbd: unlocked iface_list free during server reset vs FSCTL_QUERY_NETWORK_INTERFACE_INFO traversal -> use-after-free (kernel oops) 朱浩
2026-09-23 9:22 ` Greg KH [this message]
[not found] ` <AK2AhgCLKwK9zwB7Ti6KtqpK.3.1790166059428.Hmail.2401112100@stu.pku.edu.cn>
2026-09-23 12:35 ` Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026092344-muck-retainer-dd6d@gregkh \
--to=greg@kroah.com \
--cc=linkinjeon@kernel.org \
--cc=linkinjeon@samba.org \
--cc=linux-cifs@vger.kernel.org \
--cc=security@kernel.org \
--cc=sfrench@samba.org \
--cc=smfrench@gmail.com \
--cc=zhuhao@stu.pku.edu.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox