Received: by 2002:ab2:6c55:0:b0:1fd:c486:4f03 with SMTP id v21csp290632lqp; Wed, 12 Jun 2024 01:23:17 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCUSHcmYmISapyU2GnI000ru4aWdZgt7Zs+rGc1CLwvr8Pr+uCc/qYtE7/fO4VkVWHmyEWb/stcrf6FGajTu2Eo/e37gDfysdwosSfNCrw== X-Google-Smtp-Source: AGHT+IG4+P9AQ4kn383BeP3gAidrWwdBuIiIHJCZX6/AdSdSxHyIYv9uZNC+APuRxDzUU1kqY8gl X-Received: by 2002:a05:6214:4383:b0:6b2:9e53:fe3f with SMTP id 6a1803df08f44-6b29e53ff56mr2405626d6.30.1718180597026; Wed, 12 Jun 2024 01:23:17 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1718180597; cv=pass; d=google.com; s=arc-20160816; b=zNBjn3WrakqScbxaAujdQ/LdFfbIK3PIJM3TdgyT1hM2ZjnmkaqtreD89o9HoOc1wl 7sotgu0bzF61pAyVXAWZLFUElApBewwIy2OEFsGSG/sbEeW4FFPnUQNKu3WtU0H/d6hM cjdx0MBLweugk7F0DqVacCE4Mf9katZZqWNSLkzA95F7zY3Pqipisk66BJvjPlqka90B MBX5ZN0BYUsVDG4AE+p2FwPk1f1xQBrw9zOxXUY7tUBw/oibkZzd+MFIE2FIitE6GLrN yK3Fn32j0Yyq0Tc4ysBwzbtsErUaiTr5Rj84t88RBC0kMNCLdJYc0TBlJZGls+QQUbFA 1EXA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=in-reply-to:content-disposition:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:message-id:subject:cc :to:from:date:dkim-signature; bh=OJq/IbfslkV/c7HeFTpqtCSCJ84gQV8NPJ9H3+2mij0=; fh=sn38RUAyoubVjbXmsatCIPubP5TZz5CJD4mTmPn3k58=; b=RMIklUo/YHtwnxwdExkauQ2vJO+wXG7qwDbxVwFh2gIx6iM5MRC6AKHx6SlO7JQ9Jn nRqNIYBMbu0h+ObYCP/QArcmV0DbHzQuPCzzBIJE7MoQtntjAxWSuAtdvUDCWuw9lzp/ y8Ct3n3NzaCfIO6GQZeLz9pcRYjxFqrI6PEh1neRjryqh0AP+6ZTBUGFlcSigGB/xoHJ 8GtpQD09SJEbqEUBM57lOuwl0vLoOR2/QmNRanRhfimOZuAVRrdxP7DUgXkEvZ9tvgDK I21Jnv+AFqKqmB2Mj8ikH5lmrtYq6F6i7PZQNStxehOp774iCDLEVsOrnC+VWoWIGoKw qRhg==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=DPkpOsu1; arc=pass (i=1 dkim=pass dkdomain=linuxfoundation.org); spf=pass (google.com: domain of linux-kernel+bounces-211174-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-211174-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from ny.mirrors.kernel.org (ny.mirrors.kernel.org. [2604:1380:45d1:ec00::1]) by mx.google.com with ESMTPS id 6a1803df08f44-6b07f459e03si65841536d6.46.2024.06.12.01.23.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Jun 2024 01:23:17 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-211174-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) client-ip=2604:1380:45d1:ec00::1; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=DPkpOsu1; arc=pass (i=1 dkim=pass dkdomain=linuxfoundation.org); spf=pass (google.com: domain of linux-kernel+bounces-211174-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-211174-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ny.mirrors.kernel.org (Postfix) with ESMTPS id BD3FE1C221AF for ; Wed, 12 Jun 2024 08:23:16 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 40B6416D4F0; Wed, 12 Jun 2024 08:21:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="DPkpOsu1" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 64D3316D4E3; Wed, 12 Jun 2024 08:21:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718180483; cv=none; b=J5edDTVjKVMn5mI+yQbY8G8NWo/pOrdtF1zOas1KwioAbK5QulnKpCZ1RttNeJ3EoFSAfdbOFfX0dFYgo/+Yvxu9/dp+sZMsocsylxu6sTrp/ER38TYYOnKqYLoJc0E0+QJTaWdy2Zm/xn3MvJarPzcswGEv64sVzEwZ8gHzKZU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718180483; c=relaxed/simple; bh=qqjFVlI1kvRAd0RLwb7ZLf1rAt+ZLBSLoAbsYcj19w4=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=teBvBJjtCkGh6WT51rbpnOJwkWzg7SHpm74dNDfXhArV8EA0iO1FB0en7jul+rwIAciSt8Zhw2jI+Thjj4OXbJ3IfsZ7yFEpso3XeA1J0aJ5fsz+2tD4pVV6ba4H3i0ovQL5AtMNMpmTAHV/RUUhmzWoBXNTNQZGRiRkomJGRf0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=DPkpOsu1; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id B59DFC3277B; Wed, 12 Jun 2024 08:21:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1718180483; bh=qqjFVlI1kvRAd0RLwb7ZLf1rAt+ZLBSLoAbsYcj19w4=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=DPkpOsu1Awpn3tBZCkYVJIBzUNSBtj7HNwsgFsQ/sDnRANvUaEXt37RB6sNPka2lA ZcQN8BRNXwm6PBkEniOYbRCW0TwBBdCEpL7Ym63sqsuYmAhAp/Q5FDNjDwPm5u7hyh xyVnAsUDRsJ32+6AATphEOxU9HCi6Jc1IJCDoexo= Date: Wed, 12 Jun 2024 10:21:20 +0200 From: Greg Kroah-Hartman To: Wang Zhaolong Cc: cve@kernel.org, linux-kernel@vger.kernel.org, linux-cve-announce@vger.kernel.org Subject: Re: CVE-2023-52666: ksmbd: fix potential circular locking issue in smb2_set_ea() Message-ID: <2024061202-audience-unblessed-c27d@gregkh> References: <2024051727-CVE-2023-52666-802b@gregkh> <85948141-5eae-bb3d-cb39-62fc6ddfe476@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <85948141-5eae-bb3d-cb39-62fc6ddfe476@huawei.com> On Tue, Jun 11, 2024 at 07:30:20PM +0800, Wang Zhaolong wrote: > > > > > The Linux kernel CVE team recommends that you update to the latest > > stable kernel version for this, and many other bugfixes. Individual > > changes are never tested alone, but rather are part of a larger kernel > > release. Cherry-picking individual commits is not recommended or > > supported by the Linux kernel community at all. If however, updating to > > the latest release is impossible, the individual changes to resolve this > > issue can be found at these commits: > > https://git.kernel.org/stable/c/5349fd419e4f685d609c85b781f2b70f0fb14848 > > https://git.kernel.org/stable/c/e61fc656ceeaec65f19a92f0ffbeb562b7941e8d > > https://git.kernel.org/stable/c/e9ec6665de8f706b4f4133b87b2bd02a159ec57b > > https://git.kernel.org/stable/c/ecfd93955994ecc2a1308f5ee4bd90c7fca9a8c6 > > https://git.kernel.org/stable/c/6fc0a265e1b932e5e97a038f99e29400a93baad0 > > Hello. > > Is this a valid CVE patch? > > I noticed that the introduced `get_write` is not being used within the > function, and there are no follow-up patches addressing this. Yeah, that's odd. No, it's not, I'll go revoke this now, thanks for noticing! greg k-h