Re: [PATCH v2] cifs: fix use-after-free of server info on cifs_ses_add_channel error
From: Namjae Jeon
Date: Sat Oct 10 2026 - 09:11:46 EST
On Sat, Oct 10, 2026 at 12:29 PM Henry Martin <bsdhenrymartin@xxxxxxxxx> wrote:
>
> The error path of cifs_ses_add_channel() calls cifs_put_tcp_session()
> before cifs_chan_clear_need_reconnect(). The latter reaches
> cifs_ses_get_chan_index(), which dereferences server->terminate; if
> the put was the final reference, TCP_Server_Info is already freed and
> this is a use-after-free. Same put-then-use pattern as the recently
> fixed sibling in commit 717e0a25036b ("cifs: Fix server use-after-free
> in cifs_chan_skip_or_disable()").
>
> Move the put last, but do not read chan->server after dropping
> chan_lock: chan points into ses->chans[], and once chan_count is
> decremented a concurrent add_channel can reuse the slot and overwrite
> the pointer, so the put would act on the new channel's server. Cache
> the pointer under chan_lock, clear the reconnect bit and decrement
> chan_count while still holding the reference, and release it after
> the unlock.
>
> This issue was discovered by Tencent CodeBuddy Security.
>
> Cc: stable@xxxxxxxxxxxxxxx
> Fixes: ee1d21794e55a ("cifs: handle when server stops supporting multichannel")
> Signed-off-by: Henry Martin <bsdhenrymartin@xxxxxxxxx>
Reviewed-by: Namjae Jeon <linkinjeon@xxxxxxxxxx>
Thanks!