In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smbgrantoplock()
smbgrantoplock() has two issues in the oplock publication sequence:
1) opinfo is linked into ci->moplist (via opinfoadd) before addleasegloballist() is called. If addleasegloballist() fails (kmalloc returns NULL), the error path frees the opinfo via freeopinfo() while it is still linked in ci->moplist. Concurrent moplist readers (opinfogetlist, or direct iteration in smbbreakalllevIIoplock) dereference the freed node.
2) opinfo->ofp is assigned after addleasegloballist() publishes the opinfo on the global lease list. A concurrent findsameleasekey() can walk the lease list and dereference opinfo->ofp->fci while ofp is still NULL.
Fix by restructuring the publication sequence to eliminate post-publish failure:
- Set opinfo->ofp before any list publication (fixes NULL deref). - Preallocate leasetable via allocleasetable() before opinfoadd() so addleasegloballist() becomes infallible after publication. - Keep the original moplist publication order (opinfoadd before lease list) so concurrent opens via sameclienthaslease() and opinfogetlist() still see the in-flight grant. - Use opinfoput() instead of freeopinfo() on errout so that the RCU-deferred free path is used.
This also requires splitting addleasegloballist() to take a preallocated leasetable and changing its return type from int to void, since it can no longer fail.
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate EaNameLength in smb2getea()
smb2getea() reads eareq->EaNameLength from the client request and passes it directly to strncmp() as the comparison length without verifying that the length of the name really is the size of the input buffer received.
Fix this up by properly checking the size of the name based on the value received and the overall size of the request, to prevent a later strncmp() call to use the length as a "trusted" size of the buffer. Without this check, uninitialized heap values might be slowly leaked to the client.
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use checkaddoverflow() to prevent u16 DACL size overflow
setposixaclentriesdacl() and setntacldacl() accumulate ACE sizes in u16 variables. When a file has many POSIX ACL entries, the accumulated size can wrap past 65535, causing the pointer arithmetic (char )pndace + size to land within already-written ACEs. Subsequent writes then overwrite earlier entries, and pndacl->size gets a truncated value.
Use checkaddoverflow() at each accumulation point to detect the wrap before it corrupts the buffer, consistent with existing checkmuloverflow() usage elsewhere in smbacl.c.