From: ChenXiaoSong <chenxiaosong@chenxiaosong.com>
To: smfrench@gmail.com, linkinjeon@kernel.org, tom@talpey.com,
senozhatsky@chromium.org, obnred@gmail.com,
Bahubali B Gumaji <bahubali.bg@samsung.com>
Cc: linux-cifs@vger.kernel.org, samba-technical@lists.samba.org,
ChenXiaoSong <chenxiaosong@kylinos.cn>
Subject: Re: [PATCH] smb/server: fix use-after-free in ksmbd_conn_transport_destroy()
Date: Thu, 13 Aug 2026 20:38:10 +0800 [thread overview]
Message-ID: <fc4bcb05-866d-471e-b07f-61575d46bb13@chenxiaosong.com> (raw)
In-Reply-To: <20260813104042.170080-1-chenxiaosong@chenxiaosong.com>
Fixes: b38f99c1217a ("ksmbd: add procfs interface for runtime monitoring
and statistics")
在 2026/8/13 18:40, ChenXiaoSong 写道:
> From: ChenXiaoSong <chenxiaosong@kylinos.cn>
>
> Reproducer (Link[1]):
>
> 1. Build kernel with CONFIG_KASAN=y
> 2. server: systemctl start ksmbd
> 3. client: mount -t cifs //localhost/export /mnt
> 4. client: umount /mnt
> 5. server: modprobe -r ksmbd
>
> The error message is as follows:
>
> ==================================================================
> BUG: KASAN: slab-use-after-free in proc_remove+0x3e/0x80
> Read of size 8 at addr ffff88810654e098 by task modprobe/785
> ...
> Call Trace:
> <TASK>
> __dump_stack+0x19/0x30
> dump_stack_lvl+0x49/0x60
> print_address_description+0x7b/0x200
> print_report+0x5b/0x70
> kasan_report+0xed/0x130
> __asan_report_load8_noabort+0x18/0x20
> proc_remove+0x3e/0x80
> ksmbd_conn_transport_destroy+0x2b/0x320 [ksmbd]
> cleanup_module+0x33/0xe00 [ksmbd]
> __se_sys_delete_module+0x276/0x400
> __x64_sys_delete_module+0x5f/0x70
> x64_sys_call+0x2675/0x3030
> do_syscall_64+0xf0/0x3b0
> entry_SYSCALL_64_after_hwframe+0x76/0x7e
> RIP: 0033:0x7f5b56d2b02b
> ...
> </TASK>
>
> Allocated by task 159:
> kasan_save_track+0x2f/0x70
> kasan_save_alloc_info+0x40/0x50
> __kasan_slab_alloc+0x52/0x70
> kmem_cache_alloc_noprof+0x168/0x3e0
> __proc_create+0x20b/0x710
> proc_create_single_data+0x78/0x150
> ksmbd_proc_create+0x24/0x30 [ksmbd]
> ksmbd_conn_transport_init+0x4f/0x80 [ksmbd]
> server_ctrl_handle_work+0x64/0x2c0 [ksmbd]
> process_scheduled_works+0x788/0xec0
> worker_thread+0x894/0xc10
> kthread+0x2e5/0x3c0
> ret_from_fork+0x168/0x4f0
> ret_from_fork_asm+0x1a/0x30
>
> Freed by task 785:
> kasan_save_track+0x2f/0x70
> kasan_save_free_info+0x4a/0x60
> __kasan_slab_free+0x47/0x70
> kmem_cache_free+0x122/0x410
> pde_put+0xfd/0x160
> remove_proc_subtree+0x365/0x540
> proc_remove+0x6a/0x80
> ksmbd_proc_cleanup+0x1f/0x60 [ksmbd]
> cleanup_module+0x18/0xe00 [ksmbd]
> __se_sys_delete_module+0x276/0x400
> __x64_sys_delete_module+0x5f/0x70
> x64_sys_call+0x2675/0x3030
> do_syscall_64+0xf0/0x3b0
> entry_SYSCALL_64_after_hwframe+0x76/0x7e
> ==================================================================
>
> Reported-by: Kyenghwan Hwang <obnred@gmail.com>
> Link[1]: https://lore.kernel.org/linux-cifs/8ea028f5-90f4-4d21-b1ac-a343f0f04d88@chenxiaosong.com/
> Signed-off-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
> ---
> fs/smb/server/server.c | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/fs/smb/server/server.c b/fs/smb/server/server.c
> index 0ccd123ba418..d619d1f22601 100644
> --- a/fs/smb/server/server.c
> +++ b/fs/smb/server/server.c
> @@ -596,11 +596,16 @@ static int ksmbd_server_shutdown(void)
> {
> WRITE_ONCE(server_conf.state, SERVER_STATE_SHUTTING_DOWN);
>
> - ksmbd_proc_cleanup();
> class_unregister(&ksmbd_control_class);
> ksmbd_workqueue_destroy();
> ksmbd_ipc_release();
> ksmbd_conn_transport_destroy();
> + /*
> + * ksmbd_conn_transport_destroy() calls delete_proc_clients() and destroys
> + * sessions. ksmbd_session_destroy() removes each session's proc entry.
> + * Keep the procfs tree alive until these entries have been removed.
> + */
> + ksmbd_proc_cleanup();
> ksmbd_crypto_destroy();
> ksmbd_free_global_file_table();
> destroy_lease_table(NULL);
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
next prev parent reply other threads:[~2026-08-13 12:38 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 10:40 [PATCH] smb/server: fix use-after-free in ksmbd_conn_transport_destroy() ChenXiaoSong
2026-08-13 12:38 ` ChenXiaoSong [this message]
2026-08-13 13:32 ` Blue bird
2026-08-13 13:37 ` Blue bird
2026-08-13 13:46 ` ChenXiaoSong
2026-08-14 5:07 ` Namjae Jeon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=fc4bcb05-866d-471e-b07f-61575d46bb13@chenxiaosong.com \
--to=chenxiaosong@chenxiaosong.com \
--cc=bahubali.bg@samsung.com \
--cc=chenxiaosong@kylinos.cn \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=obnred@gmail.com \
--cc=samba-technical@lists.samba.org \
--cc=senozhatsky@chromium.org \
--cc=smfrench@gmail.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox