CVE-2024-53178: smb: Don't leak cfid when reconnect races with open_cached_dir

Published Dec 27, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

smb: Don't leak cfid when reconnect races with opencacheddir

opencacheddir() may either race with the tcon reconnection even before compoundsendrecv() or directly trigger a reconnection via SMB2openinit() or SMBqueryinfoinit().

The reconnection process invokes invalidateallcacheddirs() via cifsmarkopenfilesinvalid(), which removes all cfids from the cfids->entries list but doesn't drop a ref if haslease isn't true. This results in the currently-being-constructed cfid not being on the list, but still having a refcount of 2. It leaks if returned from opencacheddir().

Fix this by setting cfid->haslease when the ref is actually taken; the cfid will not be used by other threads until it has a valid time.

Addresses these kmemleaks:

unreferenced object 0xffff8881090c4000 (size 1024): comm "bash", pid 1860, jiffies 4295126592 hex dump (first 32 bytes): 00 01 00 00 00 00 ad de 22 01 00 00 00 00 ad de ........"....... 00 ca 45 22 81 88 ff ff f8 dc 4f 04 81 88 ff ff ..E"......O..... backtrace (crc 6f58c20f): [<ffffffff8b895a1e>] kmalloccachenoprof+0x2be/0x350 [<ffffffff8bda06e3>] opencacheddir+0x993/0x1fb0 [<ffffffff8bdaa750>] cifsreaddir+0x15a0/0x1d50 [<ffffffff8b9a853f>] iteratedir+0x28f/0x4b0 [<ffffffff8b9a9aed>] x64sysgetdents64+0xfd/0x200 [<ffffffff8cf6da05>] dosyscall64+0x95/0x1a0 [<ffffffff8d00012f>] entrySYSCALL64afterhwframe+0x76/0x7e unreferenced object 0xffff8881044fdcf8 (size 8): comm "bash", pid 1860, jiffies 4295126592 hex dump (first 8 bytes): 00 cc cc cc cc cc cc cc ........ backtrace (crc 10c106a9): [<ffffffff8b89a3d3>] kmallocnodetrackcallernoprof+0x363/0x480 [<ffffffff8b7d7256>] kstrdup+0x36/0x60 [<ffffffff8bda0700>] opencacheddir+0x9b0/0x1fb0 [<ffffffff8bdaa750>] cifsreaddir+0x15a0/0x1d50 [<ffffffff8b9a853f>] iteratedir+0x28f/0x4b0 [<ffffffff8b9a9aed>] x64sysgetdents64+0xfd/0x200 [<ffffffff8cf6da05>] dosyscall64+0x95/0x1a0 [<ffffffff8d00012f>] entrySYSCALL64afterhwframe+0x76/0x7e

And addresses these BUG splats when unmounting the SMB filesystem:

BUG: Dentry ffff888140590ba0{i=1000000000080,n=/} still in use (2) [unmount of cifs cifs] WARNING: CPU: 3 PID: 3433 at fs/dcache.c:1536 umountcheck+0xd0/0x100 Modules linked in: CPU: 3 UID: 0 PID: 3433 Comm: bash Not tainted 6.12.0-rc4-g850925a8133c-dirty #49 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 RIP: 0010:umountcheck+0xd0/0x100 Code: 8d 7c 24 40 e8 31 5a f4 ff 49 8b 54 24 40 41 56 49 89 e9 45 89 e8 48 89 d9 41 57 48 89 de 48 c7 c7 80 e7 db ac e8 f0 72 9a ff <0f> 0b 58 31 c0 5a 5b 5d 41 5c 41 5d 41 5e 41 5f e9 2b e5 5d 01 41 RSP: 0018:ffff88811cc27978 EFLAGS: 00010286 RAX: 0000000000000000 RBX: ffff888140590ba0 RCX: ffffffffaaf20bae RDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffff8881f6fb6f40 RBP: ffff8881462ec000 R08: 0000000000000001 R09: ffffed1023984ee3 R10: ffff88811cc2771f R11: 00000000016cfcc0 R12: ffff888134383e08 R13: 0000000000000002 R14: ffff8881462ec668 R15: ffffffffaceab4c0 FS: 00007f23bfa98740(0000) GS:ffff8881f6f80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000556de4a6f808 CR3: 0000000123c80000 CR4: 0000000000350ef0 Call Trace: <TASK> dwalk+0x6a/0x530 shrinkdcacheforumount+0x6a/0x200 genericshutdownsuper+0x52/0x2a0 killanonsuper+0x22/0x40 cifskillsb+0x159/0x1e0 deactivatelockedsuper+0x66/0xe0 cleanupmnt+0x140/0x210 taskworkrun+0xfb/0x170 syscallexittousermode+0x29f/0x2b0 dosyscall64+0xa1/0x1a0 entrySYSCALL64afterhwframe+0x76/0x7e RIP: 0033:0x7f23bfb93ae7 Code: ff ff ff ff c3 66 0f 1f 44 00 00 48 8b 0d 11 93 0d 00 f7 d8 64 89 01 b8 ff ff ff ff eb bf 0f 1f 44 00 00 b8 50 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e9 92 0d 00 f7 d8 64 89 ---truncated---

Other sources

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

5 affected componentsFixes available
Linux Linux kernel
debian/linux<=6.1.129-1, <=6.1.135-1
5.10.223-15.10.234-16.12.25-1
Linux Linux kernel>=6.1<6.6.64
Linux Linux kernel>=6.7<6.11.11
Linux Linux kernel>=6.12<6.12.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.12.25-1
  2. Configuration

    Fix the cfid leak by setting cfid->has_lease when the ref is actually taken. This ensures cfid is not used by other threads until it has a valid time.

    Linux kernel CIFS/SMB (cifs) cfid->has_lease = set when the ref is actually taken

Event History

Dec 27, 2024
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
DescriptionSeverity
Data Sourced
via NVD·02:15 PM
Description
Data Sourced
via NVD·02:15 PM
RemedySeverityWeaknessAffected Software
Apr 17, 2025
Data Sourced
via Launchpad·01:11 AM
Description
May 3, 2025
Data Sourced
via Ubuntu·01:12 AM
RemedyDescriptionSeverityAffected Software
Jan 11, 58561
Event
via MITRE·03:20 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-53178?

CVE-2024-53178 is classified with a moderate severity level due to potential information disclosure risks.

2

How do I fix CVE-2024-53178?

To fix CVE-2024-53178, upgrade to the latest recommended versions of the Linux kernel, specifically 5.10.223-1, 5.10.226-1, 6.12.12-1, or 6.12.15-1.

3

What systems are affected by CVE-2024-53178?

CVE-2024-53178 affects the Linux kernel across various versions prior to the fixed releases.

4

Is CVE-2024-53178 exploitable?

CVE-2024-53178 may be exploitable in scenarios where the SMB protocol is in use, particularly involving directory reconnections.

5

What impact does CVE-2024-53178 have on user data?

CVE-2024-53178 could potentially lead to the unintentional leakage of sensitive information during reconnection processes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203