|
Paulo Alcantara |
a50abb |
From: Paulo Alcantara <pc@cjr.nz>
|
|
Paulo Alcantara |
a50abb |
Date: Tue, 10 Jan 2023 20:35:46 -0300
|
|
Paulo Alcantara |
a50abb |
Subject: [PATCH] cifs: fix potential memory leaks in session setup
|
|
Paulo Alcantara |
a50abb |
Git-commit: 2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f
|
|
Paulo Alcantara |
a50abb |
References: bsc#1193629
|
|
Paulo Alcantara |
a50abb |
Patch-mainline: v6.2-rc4
|
|
Paulo Alcantara |
a50abb |
|
|
Paulo Alcantara |
a50abb |
Make sure to free cifs_ses::auth_key.response before allocating it as
|
|
Paulo Alcantara |
a50abb |
we might end up leaking memory in reconnect or mounting.
|
|
Paulo Alcantara |
a50abb |
|
|
Paulo Alcantara |
a50abb |
Signed-off-by: Paulo Alcantara (SUSE) <pc@cjr.nz>
|
|
Paulo Alcantara |
a50abb |
Signed-off-by: Steve French <stfrench@microsoft.com>
|
|
Paulo Alcantara |
a50abb |
Acked-by: Paulo Alcantara <palcantara@suse.de>
|
|
Paulo Alcantara |
a50abb |
---
|
|
Paulo Alcantara |
a50abb |
fs/cifs/cifsencrypt.c | 1 +
|
|
Paulo Alcantara |
a50abb |
fs/cifs/sess.c | 2 ++
|
|
Paulo Alcantara |
a50abb |
fs/cifs/smb2pdu.c | 1 +
|
|
Paulo Alcantara |
a50abb |
3 files changed, 4 insertions(+)
|
|
Paulo Alcantara |
a50abb |
|
|
Paulo Alcantara |
a50abb |
diff --git a/fs/cifs/cifsencrypt.c b/fs/cifs/cifsencrypt.c
|
|
Paulo Alcantara |
a50abb |
index 5db73c0f792a..cbc18b4a9cb2 100644
|
|
Paulo Alcantara |
a50abb |
--- a/fs/cifs/cifsencrypt.c
|
|
Paulo Alcantara |
a50abb |
+++ b/fs/cifs/cifsencrypt.c
|
|
Paulo Alcantara |
a50abb |
@@ -278,6 +278,7 @@ build_avpair_blob(struct cifs_ses *ses, const struct nls_table *nls_cp)
|
|
Paulo Alcantara |
a50abb |
* ( for NTLMSSP_AV_NB_DOMAIN_NAME followed by NTLMSSP_AV_EOL ) +
|
|
Paulo Alcantara |
a50abb |
* unicode length of a netbios domain name
|
|
Paulo Alcantara |
a50abb |
*/
|
|
Paulo Alcantara |
a50abb |
+ kfree_sensitive(ses->auth_key.response);
|
|
Paulo Alcantara |
a50abb |
ses->auth_key.len = size + 2 * dlen;
|
|
Paulo Alcantara |
a50abb |
ses->auth_key.response = kzalloc(ses->auth_key.len, GFP_KERNEL);
|
|
Paulo Alcantara |
a50abb |
if (!ses->auth_key.response) {
|
|
Paulo Alcantara |
a50abb |
diff --git a/fs/cifs/sess.c b/fs/cifs/sess.c
|
|
Paulo Alcantara |
a50abb |
index 0b842a07e157..c47b254f0d1e 100644
|
|
Paulo Alcantara |
a50abb |
--- a/fs/cifs/sess.c
|
|
Paulo Alcantara |
a50abb |
+++ b/fs/cifs/sess.c
|
|
Paulo Alcantara |
a50abb |
@@ -815,6 +815,7 @@ int decode_ntlmssp_challenge(char *bcc_ptr, int blob_len,
|
|
Paulo Alcantara |
a50abb |
return -EINVAL;
|
|
Paulo Alcantara |
a50abb |
}
|
|
Paulo Alcantara |
a50abb |
if (tilen) {
|
|
Paulo Alcantara |
a50abb |
+ kfree_sensitive(ses->auth_key.response);
|
|
Paulo Alcantara |
a50abb |
ses->auth_key.response = kmemdup(bcc_ptr + tioffset, tilen,
|
|
Paulo Alcantara |
a50abb |
GFP_KERNEL);
|
|
Paulo Alcantara |
a50abb |
if (!ses->auth_key.response) {
|
|
Paulo Alcantara |
a50abb |
@@ -1428,6 +1429,7 @@ sess_auth_kerberos(struct sess_data *sess_data)
|
|
Paulo Alcantara |
a50abb |
goto out_put_spnego_key;
|
|
Paulo Alcantara |
a50abb |
}
|
|
Paulo Alcantara |
a50abb |
|
|
Paulo Alcantara |
a50abb |
+ kfree_sensitive(ses->auth_key.response);
|
|
Paulo Alcantara |
a50abb |
ses->auth_key.response = kmemdup(msg->data, msg->sesskey_len,
|
|
Paulo Alcantara |
a50abb |
GFP_KERNEL);
|
|
Paulo Alcantara |
a50abb |
if (!ses->auth_key.response) {
|
|
Paulo Alcantara |
a50abb |
diff --git a/fs/cifs/smb2pdu.c b/fs/cifs/smb2pdu.c
|
|
Paulo Alcantara |
a50abb |
index 727f16b426be..4b71f4a92f76 100644
|
|
Paulo Alcantara |
a50abb |
--- a/fs/cifs/smb2pdu.c
|
|
Paulo Alcantara |
a50abb |
+++ b/fs/cifs/smb2pdu.c
|
|
Paulo Alcantara |
a50abb |
@@ -1453,6 +1453,7 @@ SMB2_auth_kerberos(struct SMB2_sess_data *sess_data)
|
|
Paulo Alcantara |
a50abb |
|
|
Paulo Alcantara |
a50abb |
/* keep session key if binding */
|
|
Paulo Alcantara |
a50abb |
if (!is_binding) {
|
|
Paulo Alcantara |
a50abb |
+ kfree_sensitive(ses->auth_key.response);
|
|
Paulo Alcantara |
a50abb |
ses->auth_key.response = kmemdup(msg->data, msg->sesskey_len,
|
|
Paulo Alcantara |
a50abb |
GFP_KERNEL);
|
|
Paulo Alcantara |
a50abb |
if (!ses->auth_key.response) {
|
|
Paulo Alcantara |
a50abb |
--
|
|
Paulo Alcantara |
a50abb |
2.39.0
|
|
Paulo Alcantara |
a50abb |
|
|
Paulo Alcantara |
a50abb |
|