Received: by 2002:a89:2c3:0:b0:1ed:23cc:44d1 with SMTP id d3csp944615lqs; Wed, 6 Mar 2024 01:17:21 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCUHn/qfN2DaJS57CJa6qJbb6DTIyF8o9cRFN0i8ifR6WuoQ2AnLrmm7CCEoFs21qjVDxfshosPR4lkZ2wHetUjp0pDVSwrOTVvP5bPVYg== X-Google-Smtp-Source: AGHT+IFav5OzUx/JAalnP3yeqYayGGk7OLkOhhXtWLWp8BXQ3g2xvBUfxxOf/QhsFIGDaDP9PEDv X-Received: by 2002:a05:6402:2318:b0:565:1049:c013 with SMTP id l24-20020a056402231800b005651049c013mr9904460eda.10.1709716641233; Wed, 06 Mar 2024 01:17:21 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1709716641; cv=pass; d=google.com; s=arc-20160816; b=YDXhaXX1NEcLhKNzpGKU6Q57q/4pat5XEG00f23PLeoW8jTtPdTbiRVHFUESTlSGWA vbJiPiMvMSUssDCL0FxX24uZP7Pw6Tot5dUZgOyzcMzWWQIaO2Vs265UJ6dqjFj/UVjN vM61rXGHtgs4PYC5eFjM2YWhQttG9LRvNQuUPJSZAKf7Ueb+qy3AXBDos9jb1oINZ6qB zzfaqS8YTkhuZ499Ut5iK8cl+V3iTyYg6OsfoDRVY4BwMQiOWG9VgcbcRZJTPcbyALZl RNSbHa8vtXNf5v0rXfa7VJqD9Yt4uKuRd65qUqsAKKTUzUf5rzXtvuR/5jjwM3D8wVfo U+tA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=in-reply-to:content-disposition:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:message-id:subject:cc :to:from:date:dkim-signature; bh=ZQVi9vv2Jolo4vF9x1jChCNmIxMBCM7Fucm0CsOyk4I=; fh=PTOz5QbKFm4TPqgP4gKrm7QbyLk7UcNRDHyoz7quir4=; b=z1TvCVkCkJ6ZQvqErLiIOU0Fub3plvKOmmAdt4fgJOQghu7DipuXJCpfLIt8g/XbnN nLYtfKBYMb49sboGSaO9qCSRfqZdaWA8P/X6T1wMtMJD2AoupYu0blXuRng94ZGPdiH2 hUlnyp/sDtrX1B6+AW3v91gwkqiHR+RPq4dlwIndCct6bfgJNOV3kLck8k7QQUtPphPO BHDXuloaLXbNaJTrspn1DdkUKSJVbdOIF6AVy5V3GF7bsBTyVuzcScmDbSIqZ8aU6Hrr +GAO5i43kkdQdq/SEjcWpnfNTBLZ0eY1+01Z05tJpDs/bUdL+Qx14ASwUnJ1AB8VtKZs ugHA==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=Q27lC3TZ; arc=pass (i=1 dkim=pass dkdomain=linuxfoundation.org); spf=pass (google.com: domain of linux-kernel+bounces-93606-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-93606-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id e17-20020a056402191100b00567f9411265si101430edz.248.2024.03.06.01.17.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 06 Mar 2024 01:17:21 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-93606-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=Q27lC3TZ; arc=pass (i=1 dkim=pass dkdomain=linuxfoundation.org); spf=pass (google.com: domain of linux-kernel+bounces-93606-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-93606-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 790961F26CC6 for ; Wed, 6 Mar 2024 09:17:00 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id ACA0C5DF02; Wed, 6 Mar 2024 09:16:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Q27lC3TZ" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D33EB5D91A for ; Wed, 6 Mar 2024 09:16:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709716593; cv=none; b=EEA1RTkvgWYPgVE6uNnl6wfWm5TaSmIyKvlknD3dxrpfIgL39oa7w1DqyBuLUjpXf3lgck8olJ3DFmBjv5mmCk7z6tLgpobKiQuqDm/OUYoKiWvxZQicbFK9HZGzbEdY0YjHw2WZSy6ONuMiEFEA9WIA53gCa3sQyrfSbIXGiKg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709716593; c=relaxed/simple; bh=AxT/q9GfqhNnP2P8qI4TfjdaZ0cJ/bFkdt1x4Rv1YwM=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Y/uYsaA8CxHCgs1etMAcYWNIBRwWev3iwegAfUXSBf6atX4iQEw5jXwpaeOhy4yjj4gDIh5O1fGNe3p2/1IBEH0zaog4j/5V+p4u0lseVh/lukHOWorjoByygC1gvzzm5TkQFciEr8ur4OiZOQ6X/Q0ubsbM3IPQipLWXmLOAi0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Q27lC3TZ; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id F35FFC433F1; Wed, 6 Mar 2024 09:16:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1709716593; bh=AxT/q9GfqhNnP2P8qI4TfjdaZ0cJ/bFkdt1x4Rv1YwM=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=Q27lC3TZ9eUOVELoitFV2p9rPPsKO/di3aPgsL5ZWfXGDUhL1/wE5aDcGeaso13ax GhaGf0MTbx7L2AJfSOAbuaMMFh61vgcePVPhn1VIa8yj3k3XGgW965Sbd9wMUVLBQ0 kmAjdgCTkJvJtk55yozl/kLavdYKAD2uH7pglqEM= Date: Wed, 6 Mar 2024 09:16:30 +0000 From: Greg KH To: Red Hat Product Security Cc: security@suse.de, rfrohl@suse.de, cve@kernel.org, linux-kernel@vger.kernel.org Subject: Re: Re: CVE-2023-52572: cifs: Fix UAF in cifs_demultiplex_thread() Message-ID: <2024030628-skyline-contently-4b85@gregkh> References: <15436477.7601.1709663408600@app142018.ycg3.service-now.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <15436477.7601.1709663408600@app142018.ycg3.service-now.com> On Tue, Mar 05, 2024 at 10:30:08AM -0800, Red Hat Product Security wrote: > > Hello Robert, > Thank you for reaching to Red Hat Product Security. > I have reviewed the flaws, CVE-2023-1192 has the correct patch used in the reference. What do you mean by "reference"? CVE-2023-1192 points to a patch for a totally different filesystem (ntfs3). Will that be fixed? And please stop responding in HTML format, the mailing lists reject this :( thanks, greg k-h