[PATCH] ksmbd: zero the object ID before filling FS_OBJECT_ID_INFORMATION

From: Aleksandr Khromov

Date: Fri Aug 21 2026 - 10:05:15 EST


FS_OBJECT_ID_INFORMATION reports 64 bytes to the client, so all 16 bytes
of object_id_info::objid are sent. When the volume UUID is not available
only sizeof(stfs.f_fsid) (8 bytes) is copied, and the remaining 8 bytes
are whatever the response buffer holds.

The response buffer is zeroed on allocation (kzalloc()/kvzalloc()), so
for a standalone request the tail is zero. In a compound request it need
not be: the offset of the next response is advanced by the length pinned
for the previous one, so if a preceding command wrote its reply into the
buffer and then failed, smb2_set_err_rsp() pins only the short error
response and the next reply lands inside the area already written. Only
the header is cleared there:

memset((char *)rsp_hdr, 0, sizeof(struct smb2_hdr) + 2);

Clear the field before filling it in.

Fixes: 3a64125730ca ("ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Aleksandr Khromov <haa@xxxxxxxxx>
---
fs/smb/server/smb2pdu.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 76f63f9adc72..6f5f4a399bde 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -6093,6 +6093,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,

info = (struct object_id_info *)(rsp->Buffer);

+ memset(info->objid, 0, sizeof(info->objid));
if (path.mnt->mnt_sb->s_uuid_len == 16)
memcpy(info->objid, path.mnt->mnt_sb->s_uuid.b,
path.mnt->mnt_sb->s_uuid_len);
--
2.48.1