Re: [PATCH] smb: client: avoid NULL resp_iov dereference
From: Dan Carpenter
Date: Sun Sep 27 2026 - 10:54:49 EST
On Sat, Sep 26, 2026 at 01:22:08PM +0000, Zihan Xi wrote:
> compound_send_recv() only populates response vectors when resp_iov is
> non-NULL. The final pre-authentication hash update nevertheless
> dereferences resp_iov[0] whenever all compound requests complete.
>
> Guard the update with resp_iov to match the response-buffer handling and
> avoid a NULL pointer dereference on callers that do not request response
> vectors.
>
> Fixes: 62432a3f5145 ("cifs: Clean up some places where an extra kvec[] was required for rfc1002")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: kernel test robot <lkp@xxxxxxxxx>
> Reported-by: Dan Carpenter <error27@xxxxxxxxx>
> Closes: https://lore.kernel.org/all/202609241449.HlHmnZFZ-lkp@xxxxxxxxx/
Originally the idea was that I would review these and filter out
the false positives, but these days people use lei to read email so
they recieve the unfiltered warnings. The zero day bot should
probably put a "Unfiltered warning" note at the top to let people
know the warning hasn't been reviewed.
regards,
dan carpenter