Commit a060909
ksmbd: fix use-after-free in smb2_lock
commit 84d2d16 upstream.
If smb_lock->zero_len has value, ->llist of smb_lock is not delete and
flock is old one. It will cause use-after-free on error handling
routine.
Cc: stable@vger.kernel.org
Reported-by: Norbert Szetei <norbert@doyensec.com>
Tested-by: Norbert Szetei <norbert@doyensec.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>1 parent 159d059 commit a060909
1 file changed
+3
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7441 | 7441 | | |
7442 | 7442 | | |
7443 | 7443 | | |
| 7444 | + | |
| 7445 | + | |
| 7446 | + | |
7444 | 7447 | | |
7445 | 7448 | | |
7446 | 7449 | | |
7447 | 7450 | | |
7448 | | - | |
7449 | | - | |
7450 | | - | |
7451 | 7451 | | |
7452 | 7452 | | |
7453 | 7453 | | |
| |||
0 commit comments