Received: by 2002:a05:7412:98c1:b0:fa:551:50a7 with SMTP id kc1csp302907rdb; Fri, 5 Jan 2024 10:15:30 -0800 (PST) X-Google-Smtp-Source: AGHT+IEYzE9DYN5Qoi+jxIoS2WVSEqGTAL8uy4aw1bW0lT9FrxEjBG7Ddkm2Qq/qrfHn5Hbs3X3j X-Received: by 2002:a17:906:1981:b0:a26:8542:eb31 with SMTP id g1-20020a170906198100b00a268542eb31mr668636ejd.308.1704478530084; Fri, 05 Jan 2024 10:15:30 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1704478530; cv=none; d=google.com; s=arc-20160816; b=NIVvjsmRWlc66quN/XCGsEIc4D5aqm9bPAN02YMOHr1iwk7j5a4A7z3pWKN3lSghJV 9JnzsOrH3z1Mn6GsAE1QnJ8mFGqkknD058FGlujhr6p1V6x+Q00MiYnhBxjRohmZVtRr cH5NXEcnm/XgB8fflrYn1smcy9H3K9nLk7DwxxynLWkN7gYaX0QY2dUWBrHvZ8K0Y68h ZuQnErDWiQOZQQfUC+s/YIipGPHF1Q8Spx1gv1T8KJezGxwvieOfRXB9OgpKaV3RMlNM 4a33PXnuQ0MDdYZeX2bK1XOFRD0oAjdfQGo8md1xRg02+Xsl23m+VKDGeabT2JDr/B4D CVQA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=mime-version:list-unsubscribe:list-subscribe:list-id:precedence :user-agent:organization:autocrypt:references:in-reply-to:date:cc:to :from:subject:message-id:dkim-signature; bh=2o3Ip62v3wOV3nFHSl/iTJZjBG515BkwAy1lo9RbZnU=; fh=jcNsrZq4MUU2aYuD7gX/xkE1rmeoKDHqp+W0NwC+o54=; b=GrWNueP1RwpkcSVR7Zi5blv6rFgeOMNbxovYrqDhVHajcEbfikucXFN2pfuv3zPs8g DcY0PZgb/BWzT7RdfesSGWffstut3GrEDg+4EDXKin7tRzNVxGXT/s9tT8MSkcr03BVs Z2P8Op2kt21UbB/6cR3NTlNAJH+OIFx6wvAqzGLM1WV8w4IJzGaNaUGhY0RC3FfGoeXd 8qNLtuCoUBIybxDzgY7BcRLrzb4tNG1zdUuqgevJO8zuI3lrtEh4uis43CKqVKLQPEcT YiRT1+1vuHMcx4KqrwXF5WSywg6T47nc3aw05BkTXMZDgMq5liiuvruBZ2OOzacxwUMg dIwQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@debian.org header.s=smtpauto.stravinsky header.b=EZEin8Fo; spf=pass (google.com: domain of linux-kernel+bounces-18190-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-18190-linux.lists.archive=gmail.com@vger.kernel.org" Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [147.75.80.249]) by mx.google.com with ESMTPS id g11-20020a170906394b00b00a26a25cbdb5si814861eje.451.2024.01.05.10.15.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 05 Jan 2024 10:15:30 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-18190-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) client-ip=147.75.80.249; Authentication-Results: mx.google.com; dkim=pass header.i=@debian.org header.s=smtpauto.stravinsky header.b=EZEin8Fo; spf=pass (google.com: domain of linux-kernel+bounces-18190-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-18190-linux.lists.archive=gmail.com@vger.kernel.org" Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id A8B301F22197 for ; Fri, 5 Jan 2024 18:15:29 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 74CC434CEC; Fri, 5 Jan 2024 18:15:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="EZEin8Fo" X-Original-To: linux-kernel@vger.kernel.org Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E9A5C34CD3; Fri, 5 Jan 2024 18:15:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=debian.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:MIME-Version:Content-Type:References: In-Reply-To:Date:Cc:To:From:Subject:Message-ID:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=2o3Ip62v3wOV3nFHSl/iTJZjBG515BkwAy1lo9RbZnU=; b=EZEin8Fo3/JB7JYQCaxUw+BMW5 OjjnfoZxbcOd2FdY/D1kWdHI8Xe1myq78/xUXjSpz18tiHeLv4Ib1XjM9VqvuNsWdXHIf5QVG2lxT l86SQdJ738lqnChRDekkRvhYm6gk+7aq1v2yzBXMm8Dl0Weyn2hwzLWVkGWHo061Ks+Fq++iHF/T7 9XHjYG04pAqx/gPtW4+G/NeT5ZcGNMyfOtU0jqNsT2SQrnqMpkS6YSFAqptn3m8Niqn0wKxKD/MFn XqsLqcGKTRFaCW+b6uCslXmtAwjqjUGIUiE6rfxfvn0AE9VKv5CDjywegXJcrkMBOi+QfR49JhV0d 2ILTA5Ig==; Received: from authenticated user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.94.2) (envelope-from ) id 1rLoin-001t9w-4x; Fri, 05 Jan 2024 18:15:05 +0000 Message-ID: Subject: Re: Information on use-after-free in smb2_is_status_io_timeout()? From: Ben Hutchings To: Paulo Alcantara , Salvatore Bonaccorso , Steve French , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey Cc: linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org Date: Fri, 05 Jan 2024 19:14:57 +0100 In-Reply-To: <1d2bb04665d19a4722a0b9f7f552cab3@manguebit.com> References: <1d2bb04665d19a4722a0b9f7f552cab3@manguebit.com> Autocrypt: addr=benh@debian.org; prefer-encrypt=mutual; keydata=mQINBEpZoUwBEADWqNn2/TvcJO2LyjGJjMQ6VG86RTfXdfYg31Y2UnksKm81Av+MdaF37fIQUeAmBpWoRsnKL96j0G6ElNZ8Tp1SfjWiAyWFE+O6WzdDX9uaczb+SFXM5twQbjwBYbCaiHuhV7ifz33uPeJUoOcqQmNFnZWC9EbEazXtbqnU1eQcKOLUC7kO/aKlVCxr3yChQ6J2uaOKNGJqFXb/4bUUdUSqrctGbvruUCYsEBk0VU0h0VKpkvHjw2C2rBSdJ4lAyXj7XMB5AYIY7aJvueZHk9WkethA4Xy90CwYS+3fuQFk1YJLpaQ9hT3wMpRYH7Du1+oKKySakh8r9i6x9OAPEVfHidyvNkyClUVYhUBXDFwTVXeDo5cFqZwQ35yaFbhph+OU0rMMGLCGeGommZ5MiwkizorFvfWvn7mloUNV1i6Y1JLfg1S0BhEiPedcbElTsnhg5TKDMeQUmv2uPjWqiVmhOTzhynHZKPY3PGsDxvnS8H2swcmbvKVAMVQFSliWmJiiaaaiVut7ty9EnFBQq1Th4Sx6yHzmnxIlP82Hl2VM9TsCeIlirf48S7+n8TubTsZkw8L7VJSXrmQnxXEKaFhZynXLC/g+Mdvzv9gY0YbjAu05pV42XwD3YBsvK+G3S/YKGmQ0Nn0r9owcFvVbusdkUyPWtI61HBWQFHplkiRR8QARAQABtB9CZW4gSHV0Y2hpbmdzIChET0I6IDE5NzctMDEtMTEpiQI4BBMBCAAiBQJKWaJTAhsDBgsJCAcDAgYVCgkICwMEFgIBAAIeAQIXgAAKCRDnv8jslYYRCUCJEADMkiPq+lgSwisPhlP+MlXkf3biDY/4SXfZgtP69J3llQzgK56RwxPHiCOM/kKvMOEcpxR2UzGRlWPk9WE2wpJ1Mcb4/R0KrJIimjJsr27HxAUI8oC/q2mnvVFD/VytIBQmfqkEqpFUgUGJwX7Xaq520vXCsrM45+n/H FLYlIfF5YJwj9FxzhwyZyG70BcFU93PeHwyNxieIqSb9+brsuJWHF4FcVhpsjBCA9lxbkg0sAcbjxj4lduk4sNnCoEb6Y6jniKU6MBNwaqojDvo7KNMz66mUC1x0S50EjPsgAohW+zRgxFYeixiZk1o5qh+XE7H5eunHVRdTvEfunkgb17FGSEJPWPRUK6xmAc50LfSk4TFFEa9oi1qP6lMg/wuknnWIwij2EFm1KbWrpoFDZ+ZrfWffVCxyF1y/vqgtUe2GKwpe5i5UXMHksTjEArBRCPpXJmsdkG63e5FY89zov4jCA/xc9rQmF/4LBmS0/3qamInyr6gN00C/nyv6D8XMPq4bZ3cvOqzmqeQxZlX9XG6i9AmtTN6yWVjrG4rQFjqbAc71V6GQJflwnk0KT6cHvkOb2yq3YGqTOSC2NPqx1WVYFu7BcywUK1/cZwHuETehEoKMUstw3Zf+bMziUKBOyb/tQ8tmZKUZYyeBwKpdSBHcaLtSPiNPPHBZpa1Nj6tZrQjQmVuIEh1dGNoaW5ncyA8YmVuQGRlY2FkZW50Lm9yZy51az6JAjgEEwEIACIFAkpZoUwCGwMGCwkIBwMCBhUKCQgLAwQWAgEAAh4BAheAAAoJEOe/yOyVhhEJGisP/0mG2HEXyW6eXCEcW5PljrtDSFiZ99zP/SfWrG3sPO/SaQLHGkpOcabjqvmCIK4iLJ5nvKU9ZD6Tr6GMnVsaEmLpBQYrZNw2k3bJx+XNGyuPO7PAkk8sDGJo1ffhRfhhTUrfUplT8D+Bo171+ItIUW4lXPp8HHmiS6PY22H37bSU+twjTnNt0zJ7kI32ukhZxxoyGyQhQS8Oog5etnVL0+HqOpRLy5ZV/laF/XKX/MZodYHYAfzYE5sobZHPxhDsJdPXWy02ar0qrPfUmXjdZSzK96alUMiIBGWJwb0IPS+SnAxtMxY4PwiUmt9WmuXfbhWsi9NJGbhxJpwyi7T7MGU+MVxLau KLXxy04rR/KoGRA9vQW3LHihOYmwXfQ05I/HK8LL2ZZp9PjNiUMG3rbfG65LgHFgA/K0Q3z6Hp4sir3gQyz+JkEYFjeRfbTTN7MmYqMVZpThY1aiGqaNue9sF3YMa/2eiWbpOYS2Pp1SY4E1p6uF82yJ3pxpqRj82O/PFBYqPjepkh1QGkDPFfiGN+YoNI/FkttYOBsEUC9WpJC/M4jsglVwxRax7LhSHzdve1BzCvq+tVXJgoIcmQf+jWyPEaPMpQh17hBo9994r7uMl6K3hsfeJk4z4fasVdyo0BbwPECNLAUE/BOCoqSL9IbkLRCqNRMEf63qGTYE3/tB9CZW4gSHV0Y2hpbmdzIDxiZW5oQGRlYmlhbi5vcmc+iQI4BBMBCAAiBQJKWaIJAhsDBgsJCAcDAgYVCgkICwMEFgIBAAIeAQIXgAAKCRDnv8jslYYRCdseD/9lsQAG8YxiJIUARYvY9Ob/2kry3GE0vgotPNgPolVgIYviX0lhmm26H+5+dJWZaNpkMHE6/qE1wkPVQFGlX5yRgZatKNC0rWH5kRuV1manzwglMMWvCUh5ji/bkdFwQc1cuNZf40bXCk51/TgPq5WJKv+bqwXQIaTdcd3xbGvTDNFNt3LjcnptYxeHylZzBLYWcQYos/s9IpDd5/jsw3DLkALp3bOXzR13wKxlPimM6Bs0VhMdUxu3/4pLzEuIN404gPggNMh9wOCLFzUowt14ozcLIRxiPORJE9w2e2wek/1wPD+nK91HgbLLVXFvymXncD/k01t7oRofapWCGrbHkYIGkNj/FxPPXdqWIx0hVYkSC3tyfetS8xzKZGkX7DZTbGgKj5ngTkGzcimNiIVd7y3oKmW+ucBNJ8R7Ub2uQ8iLIm7NFNVtVbX7FOvLs+mul88FzP54Adk4SD844RjegVMDn3TVt+pjtrmtFomkfbjm6dIDZVWRnMGhiNb11gTfuEWOiO/xRIiAeZ3MAWln1vmWNxz pyYq5jpoT671X+I4VKh0COLS8q/2QrIow1p8mgRN5b7Cz1DIn1z8xcLJs3unvRnqvCebQuX5VtJxhL7/LgqMRzsgqgh6f8/USWbqOobLT+foIEMWJjQh+jg2DjEwtkh10WD5xpzCN0DY2TLQeQmVuIEh1dGNoaW5ncyA8YndoQGtlcm5lbC5vcmc+iQJPBBMBCAA5FiEErCspvTSmr92z9o8157/I7JWGEQkFAloYVe4CGwMGCwkIBwMCBhUKCQgLAwQWAgEAAh4BAheAAAoJEOe/yOyVhhEJ3iIQAIi4tqvz1VblcFubwa28F4oxxo4kKprId1TDVmR7DY/P02eKWLFG1yS2nR+saPUskb9wu2+kUCEEOAoO5YksgB0fYQcOTCzI1P1PyH8QWqulB4icA5BWs5im+JV+0/LjAvj8O5QYwNtTLoSS2zVgZGAom9ljlNkP1M+7Rs/zaqbhcQsczKJXDOSFpFkFmpLADyB9Y9gSFzok7tPbwMVl+MgvF0gVSoXcxPlqKXaN/l4dylQTudZ9zJX6vem9bwj7UQEEVqHgdaUw1BLit6EeRDtGR6bHmfhbcu0raujJPpeHUCEu5Ga1HJ5VwftLfpB2qOwLSfjcFkO77kVFgUhyn+dsf+uwXy1+2mAZ33dcyc85FSkCEF8pV5lHMDTHLIBOV0zglabXGYpKCjzrxZqU8KtFsnROk+5QuWaLGJK81jCpgYTn9nsEUqCtQQ8tB3JC291DagrBVgTqPtXFLeFhftwIMBou9lo85vge/8yIKVLAczlJ7A0eBVDwY/y3UTW9B+XwiITiA71bRMIqEKsO68WFT3cFm/G5LGoxERXCntEeuf+XmYZ5WcjBWyyF11unx4ZbPj7gdSrdLQxzHnpXfYs/J7s+YssnErvR8W02tjKj8L8ObQg078BqBI9DjrH9neAAYeACpZUStbsjUQuDdyup0bAEj4IMisU4Y+SFRfKbuQINBEpZoakBEACZUeVh uZF8eDcpr7cpcev2gID8bCvtd7UH0GgiI3/sHfixcNkRk/SxMrJSmMtIQu/faqYwQsuLo2WT9rW2Pw/uxovv9UvFKg4n2huTP2JJHplNhlp2QppTy5HKw4bZDn7DJ2IyzmSZ9DfUbkwy3laTR11v6anT/dydwJy4bM234vnurlGqInmH+Em1PPSM8xMeKW0wismhfoqS9yZ8qbl0BRf5LEG7/xFo/JrM70RZkW+Sethz2gkyexicp9uWmQuSal2WxB2QzJRIN+nfdU4s7mNTiSqwHBQga6D/F32p2+z2inS5T5qJRP+OPq1fRFN6aor3CKTCvc1jBAL0gy+bqxPpKNNmwEqwVwrChuTWXRz8k8ZGjViP7otV1ExFgdphCxaCLwuPtjAbasvtEECg25M5STTggslYajdDsCCKkCF9AuaXC6yqJkxA5qOlHfMiJk53rBSsM5ikDdhz0gxij7IMTZxJNavQJHEDElN6hJtCqcyq4Y6bDuSWfEXpBJ5pMcbLqRUqhqQk5irWEAN5Ts9JwRjkPNN1UadQzDvhduc/U7KcYUVBvmFTcXkVlvp/o26PrcvRp+lKtG+S9Wkt/ON0oWmg1C/I9shkCBWfhjSQ7GNwIEk7IjIp9ygHKFgMcHZ6DzYbIZ4QrZ3wZvApsSmdHm70SFSJsqqsm+lJywARAQABiQIfBBgBCAAJBQJKWaGpAhsMAAoJEOe/yOyVhhEJhHEQALBR5ntGb5Y1UB2ioitvVjRX0nVYD9iVG8X693sUUWrpKBpibwcXc1fcYR786J3G3j9KMHR+KZudulmPn8Ee5EaLSEQDIgL0JkSTbB5o2tbQasJ2E+uJ9190wAa75IJ2XOQyLokPVDegT2LRDW/fgMq5r0teS76Ll0+1x7RcoKYucto6FZu/g0DulVD07oc90GzyHNnQKcNtqTE9D07E74P0aNlpQ/QBDvwftb5UIkcaB465u6gUngnyCny311TTgfcYq6S1tNng1 /Odud1lLbOGjZHH2UI36euTpZDGzvOwgstifMvLK2EMT8ex196NH9MUL6KjdJtZ0NytdNoGm1N/3mWYrwiPpV5Vv+kn2ONin2Vrejre9+0OoA3YvuDJY0JJmzOZ4Th5+9mJQPDpQ4L4ZFa6V/zkhhbjA+/uh5X2sdJ8xsRXAcLB33ESDAb4+CW0m/kubk/GnAJnyflkYjmVnlPAPjfsq3gG4v9eBBnJd6+/QXR9+6lVImpUPC7D58ytFYwpeIM9vkQ4CpxZVQ9jyUpDTwgWQirWDJy0YAVxEzhAxRXyb/XjCSki4dD6S5VhWqoKOd4i3QREgf+rdymmscpf/Eos9sPAiwpXFPAC6Kj81pcxR2wNY8WwJWvSs6LNESSWcfPdN4VIefAiWtbhNmkE2VnQrGPbRhsBw+3A Organization: Debian Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-DI9ZQpLR802C618LbHlD" User-Agent: Evolution 3.50.2-1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Debian-User: benh --=-DI9ZQpLR802C618LbHlD Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Fri, 2024-01-05 at 11:04 -0300, Paulo Alcantara wrote: > Salvatore Bonaccorso writes: >=20 > > There is a Red Hat bugzilla report in > > https://bugzilla.redhat.com/show_bug.cgi?id=3D2154178 about a > > use-after-free in smb2_is_status_io_timeout() . While the commit noted > > initially there seems not correct, Ben Hutchings raised a question on > > more information in > > https://bugzilla.redhat.com/show_bug.cgi?id=3D2154178#c24 . > >=20 > > (there is a CVE assigned for it, CVE-2023-1192) >=20 > That is supposed to be fixed by >=20 > d527f51331ca ("cifs: Fix UAF in cifs_demultiplex_thread()") >=20 > While the commit refers to an UAF in ->is_network_name_deleted(), this > should also work for smb2_is_status_io_timeout(), AFAICT. I think that's a different UAF bug that happens to affect the same function. Ben. --=20 Ben Hutchings - Debian developer, member of kernel, installer and LTS teams --=-DI9ZQpLR802C618LbHlD Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEErCspvTSmr92z9o8157/I7JWGEQkFAmWYRyEACgkQ57/I7JWG EQmanRAAol1IPXN8Wq9jdycSGJbkSnKRVqHUnOzPvBvCmz5lZ4Cfpuzvbq12m2/3 XAAYKc5KrT9Dqlxr0T5iACGg59LWK9RA0fgJl/xQoq6yXEgqbTBE4Dwk7qSsL+Yi UqLK0EVRQaUzC2mtb/xvWDvdR0h7vv8NanaqDiMhKBX6rbI2sIourGHTX948Lpay XT6VLb0DNRd7f9PEctE5+OQaIxkYwz1Gr+HOQRXfjH+YRR1pQhdLORi35rN9UI/6 j9opsTpSjwIQorXn7OG2xnuDmdwgO7fzKoGv8VwaSbk4DuEEHN5LMQxmMKVGF/eP H6WXvb13voEVJ5ODwnprtIL9rnPD05quOhTMeIbMa1nBzqPZCG3QuqHg+WM4L4iZ f0FD7IK0x52aVWbtHOWqQhWKCMzAPjmDvSOXVihloUbKjz4BRly9GJsujJzQY8HE Bj0rbwcXdc24/tKmaoAEP7RBmohlJ7MP6QfLnVifhvBSJBRJ2Y6u/v598LIkVwA3 gz2be9gXfKnB95i6rBI4UTxj5d1k75z7pBSSm5H0v9/eBLXws/VbpItlV/1Fnmyx TqXv8KNTAMiEhfpcLln3q4yRHvRx7d5JKds/LoDxkEc5yNKJ+SJ4Nr8nL4+J9dqO P5sI3g/HOvS1DggXjkdflmhN7R+R1NnjeXZBx3XYRSUP5K3oQTE= =DwjO -----END PGP SIGNATURE----- --=-DI9ZQpLR802C618LbHlD--