From nobody Tue Sep 29 06:47:01 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 661793BBFA9 for ; Tue, 11 Aug 2026 15:46:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463194; cv=none; b=JPlqfQWtw7lbvge9bMbF1ueTNG1pHlSlIlnxrnwicLHuIwNGlUjtHOGooto1/SUfEw684NQb3RxpXzu6U5fX9Hywo2XcoD/sofi8ety9IaEgwmliU8ZlH+Bt5qIxwIQ2CGtyGn5OMhIZvtC7VXs4cNsVeVjTBHqE3xbczWVUuvw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463194; c=relaxed/simple; bh=OIMeujMnva3xLa8zdfTj7dovkhxDVkiTY4RrPZ+4Hm0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VLBra+Yjk2PeXilXd+IxbB24Fo6IC7tmQgNkDpvGurZRFH5CjND0NzbY7kIKngRY83qYOAdby9UxzIl8lLTZcl76HEulVM7kzHSzx/TtkeaxwmCsXz2OBJWui/ZPlfp2Gxu3/0QASxci7OcZ4fVJenkm6EtCL8hz4ctfPXX1s6w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=fIbUFvem; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="fIbUFvem" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786463192; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=+UbfqJIYUeVIaBv3Gu4A1tnc7IboUdmg81Nk4N2A0cs=; b=fIbUFvemT3E5IBceadzKfZ885slbODTq/JwN/Vz0duHOFQz8vf9zly/o4iHNsM/BJO0xdC cFE/V0p3pIYt5VT7u0Z57PhgtHzCPY5BzqkuDf1l9YBItHJ4aWGbVLsObk/GwK6qjh86vw fBwBwotoLK/bQNjZC2dM9Lg8fEpHHiE= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-651-481IU262OReikMdZdl2Jzw-1; Tue, 11 Aug 2026 11:46:27 -0400 X-MC-Unique: 481IU262OReikMdZdl2Jzw-1 X-Mimecast-MFC-AGG-ID: 481IU262OReikMdZdl2Jzw_1786463186 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8AED41800658; Tue, 11 Aug 2026 15:46:26 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 6CA1B3001DAF; Tue, 11 Aug 2026 15:46:24 +0000 (UTC) From: Thomas Huth To: Namjae Jeon , Steve French Cc: linux-kernel@vger.kernel.org, Sergey Senozhatsky , Tom Talpey Subject: [PATCH v2 1/5] smb: server: Clear sensitive stack and heap data in auth.c Date: Tue, 11 Aug 2026 17:46:16 +0200 Message-ID: <20260811154620.2425851-2-thuth@redhat.com> In-Reply-To: <20260811154620.2425851-1-thuth@redhat.com> References: <20260811154620.2425851-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Sensitive data like keys that are stored in stack-local arrays could be leaked via the stack to the calling functions, or via the heap when using only normal kfree() functions. There is no known vulnaribility for this right now, but it's good security style to explicitly zeroize this sensitive matieral as soon as possible to avoid that it could be exploited together with other bugs later. In calc_ntlmv2_hash(), the struct hmac_md5_ctx is normally cleared during hmac_md5_final() already, but in case of errors, this function is skipped and ctx is never zeroized, so add a memzero_explicit(&ctx, sizeof(ctx)) there to fix the problem. In ksmbd_krb5_authenticate(), the ksmbd_spnego_authen_response contains the session key in the payload. It's currently freed with plain kvfree(). Let's better use kvfree_sensitive() instead. In generate_key(), the prfhash[] array is used to calculate the key, but it's never cleared, so it leaks on the stack. Thus clear this with a memzero_explicit(), too. In ksmbd_crypt_message(), the sign[] and key[] arrays are leaked via the stack, too. Make sure to clear them via memzero_explicit() at the end. Signed-off-by: Thomas Huth --- fs/smb/server/auth.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/fs/smb/server/auth.c b/fs/smb/server/auth.c index 4e7b6f0e6b8cd..573c5c6492c97 100644 --- a/fs/smb/server/auth.c +++ b/fs/smb/server/auth.c @@ -122,6 +122,8 @@ static int calc_ntlmv2_hash(struct ksmbd_conn *conn, st= ruct ksmbd_session *sess, out: kfree(uniname); kfree(domain); + if (ret) /* Done by hmac_md5_final() already if ret =3D=3D 0 */ + memzero_explicit(&ctx, sizeof(ctx)); return ret; } =20 @@ -464,7 +466,8 @@ int ksmbd_krb5_authenticate(struct ksmbd_session *sess,= char *in_blob, *out_len =3D resp->spnego_blob_len; retval =3D 0; out: - kvfree(resp); + kvfree_sensitive(resp, sizeof(*resp) + resp->session_key_len + + resp->spnego_blob_len); return retval; } #else @@ -556,6 +559,7 @@ static void generate_key(struct ksmbd_conn *conn, const= char *sess_key, =20 hmac_sha256_final(&ctx, prfhash); memcpy(key, prfhash, key_size); + memzero_explicit(prfhash, sizeof(prfhash)); } =20 static int generate_smb3signingkey(struct ksmbd_session *sess, @@ -848,7 +852,8 @@ int ksmbd_crypt_message(struct ksmbd_work *work, struct= kvec *iov, ctx =3D ksmbd_crypto_ctx_find_ccm(); if (!ctx) { pr_err("crypto alloc failed\n"); - return -ENOMEM; + rc =3D -ENOMEM; + goto zeroize_key; } =20 if (conn->cipher_type =3D=3D SMB2_ENCRYPTION_AES128_GCM || @@ -928,5 +933,8 @@ int ksmbd_crypt_message(struct ksmbd_work *work, struct= kvec *iov, aead_request_free(req); free_ctx: ksmbd_release_crypto_ctx(ctx); +zeroize_key: + memzero_explicit(key, sizeof(key)); + memzero_explicit(sign, sizeof(sign)); return rc; } --=20 2.55.0 From nobody Tue Sep 29 06:47:01 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D0ACA1FBEA8 for ; Tue, 11 Aug 2026 15:46:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463196; cv=none; b=GsivNGmSf8El4ysTNp/hqig5j2d4xrJWPibCpaF5/T+OpCC8SX1xHIm8K2TetwC7+/TSSyW5epUIbbXW2a8jlJhLkb5M/pYULvN4f0NaTdBRpqENewqQuFth4JEyO/nIXSq71WaYh7uRGW92gbbqG9LNXa69JbQeAk+B/j/II1A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463196; c=relaxed/simple; bh=alkQrT/mp6qBDWwuI/IMtkXcvcIMzyUeSo16FQJCm5o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Hn8sRmPxSuL1ylc/D2jkpz/GQGdcb56yV/V5vztjukgHIGEOsQnspMY4N5GN/4lTJ0SkviA/FT4RPUAzyZo+8KX+cG64MdWk/g2d48T9x7laPr+eDZ1LTzWFuUL10shoRk4LkdLXkQ1r93kK7bV+tVd6GEQQm/zaHXf9jrxglus= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=cxS99fOK; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="cxS99fOK" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786463193; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gh+3eC2KDdxNiPOue5nNMywvzbbZjC53wM5BXCY+I2U=; b=cxS99fOKDce22aSGaTYx1oGpJKOC9nDTkXrWHbQmf0Ps0t/OE41Ef4vL5yWVucjxhW8jJz sXKzXOfC9XRZxzLxX9On09G1H9bW0FawKbOqJBCgz9e14ZRSh1JQLiJbOWD0hF9bEE7Hu8 W/yceVa2x0cPYalLPSgs+zOXaU0D5n8= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-193-37Mocu0lMt6yymDuv66_QQ-1; Tue, 11 Aug 2026 11:46:30 -0400 X-MC-Unique: 37Mocu0lMt6yymDuv66_QQ-1 X-Mimecast-MFC-AGG-ID: 37Mocu0lMt6yymDuv66_QQ_1786463189 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 46128195604A; Tue, 11 Aug 2026 15:46:29 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 18A893001DAF; Tue, 11 Aug 2026 15:46:26 +0000 (UTC) From: Thomas Huth To: Namjae Jeon , Steve French Cc: linux-kernel@vger.kernel.org, Sergey Senozhatsky , Tom Talpey Subject: [PATCH v2 2/5] smb: server: Make sure that passkey is not leaked on the heap in user_config.c Date: Tue, 11 Aug 2026 17:46:17 +0200 Message-ID: <20260811154620.2425851-3-thuth@redhat.com> In-Reply-To: <20260811154620.2425851-1-thuth@redhat.com> References: <20260811154620.2425851-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Use kfree_sensitive() to free the user->passkey (and the struct ksmbd_login_response in ksmbd_login_user() that contains the same information) to avoid that this information could leak somewhere else via the heap. Signed-off-by: Thomas Huth --- fs/smb/server/mgmt/user_config.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/fs/smb/server/mgmt/user_config.c b/fs/smb/server/mgmt/user_con= fig.c index cf45841d9d1b9..76b74d68369d8 100644 --- a/fs/smb/server/mgmt/user_config.c +++ b/fs/smb/server/mgmt/user_config.c @@ -27,7 +27,7 @@ struct ksmbd_user *ksmbd_login_user(const char *account) =20 user =3D ksmbd_alloc_user(resp, resp_ext); out: - kvfree(resp); + kvfree_sensitive(resp, sizeof(*resp)); return user; } =20 @@ -70,7 +70,7 @@ struct ksmbd_user *ksmbd_alloc_user(struct ksmbd_login_re= sponse *resp, =20 err_free: kfree(user->name); - kfree(user->passkey); + kfree_sensitive(user->passkey); kfree(user); return NULL; } @@ -80,7 +80,7 @@ void ksmbd_free_user(struct ksmbd_user *user) ksmbd_ipc_logout_request(user->name, user->flags); kfree(user->sgid); kfree(user->name); - kfree(user->passkey); + kfree_sensitive(user->passkey); kfree(user); } =20 --=20 2.55.0 From nobody Tue Sep 29 06:47:01 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CD0663C061C for ; Tue, 11 Aug 2026 15:46:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463201; cv=none; b=qlDduolhyUXb/jgEMRCfZaf1DVl4YQBEt9BW2WXhhhiE0vIbJBoVJKkRRIo+W79rNS1fRu+OldbyYFvIymyzfRdpW3Zl3UD7Vmg8vXMrFby+/UjcUMv5gey6VMOs71s8HhNZOFVVsWz1sKch81axGKvU9v7Il+WiSbz/Sx3hem0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463201; c=relaxed/simple; bh=bqx3BjBbvTbeuGV0qkFsGaKkfysKhy/kb4On0buQoio=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=AmbRgX4y9+oiHmblTy15MaSjUoEVBjmLSfZjH/yMedx4mOp7wY6j59ULtXM98SD5YZbu5sziY6pPiXPFcO+3zeMxUbXkt7c9146jCeCe8mDWHUZ9Y75W9dCp1e/Ezi4EOKJtJjNeio6y7iYocKP4R0scj1gT8e5FCE5N6Irky5g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=LGbbIE6q; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="LGbbIE6q" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786463198; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=xk7zF9B337l+v+zmWz075wTvLr5aI1bS+oxgsAu+NpU=; b=LGbbIE6qJiATS+O+R5HmjDNJENd/hN4XETK39ClK6TPxL8fTbtAYehU+bLowCucA8nkpIg QrRCFI3hlozq/yIayaIg/koOocQnUNLmijFYSOArV4nAEp4UyKr7CF1hiSd6vhj5Uu/6Dp GDty38VHZyM+IjMv5FL33R7JxO4QwEE= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-695-AGZOc3tTOqWniLxpJGDXEA-1; Tue, 11 Aug 2026 11:46:33 -0400 X-MC-Unique: AGZOc3tTOqWniLxpJGDXEA-1 X-Mimecast-MFC-AGG-ID: AGZOc3tTOqWniLxpJGDXEA_1786463192 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 1F23F180064C; Tue, 11 Aug 2026 15:46:32 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D476E3001DAF; Tue, 11 Aug 2026 15:46:29 +0000 (UTC) From: Thomas Huth To: Namjae Jeon , Steve French Cc: linux-kernel@vger.kernel.org, Sergey Senozhatsky , Tom Talpey Subject: [PATCH v2 3/5] smb: server: Free session data in user_session.c with kfree_sensitive() Date: Tue, 11 Aug 2026 17:46:18 +0200 Message-ID: <20260811154620.2425851-4-thuth@redhat.com> In-Reply-To: <20260811154620.2425851-1-thuth@redhat.com> References: <20260811154620.2425851-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth struct ksmbd_session contains some arrays with sensitive information, like sess_key, smb3encryptionkey, smb3decryptionkey and smb3signingkey. Thus let's make sure that this information cannot leak via the heap and use kfree_sensitive() to free it. Signed-off-by: Thomas Huth --- fs/smb/server/mgmt/user_session.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/fs/smb/server/mgmt/user_session.c b/fs/smb/server/mgmt/user_se= ssion.c index f99c86284ba3d..9cb990a22fd56 100644 --- a/fs/smb/server/mgmt/user_session.c +++ b/fs/smb/server/mgmt/user_session.c @@ -389,10 +389,10 @@ void ksmbd_session_destroy(struct ksmbd_session *sess) ksmbd_launch_ksmbd_durable_scavenger(); ksmbd_session_rpc_clear_list(sess); free_channel_list(sess); - kfree(sess->Preauth_HashValue); + kfree_sensitive(sess->Preauth_HashValue); ksmbd_release_id(&session_ida, sess->id); ida_destroy(&sess->tree_conn_ida); - kfree(sess); + kfree_sensitive(sess); } =20 struct ksmbd_session *__session_lookup(unsigned long long id) --=20 2.55.0 From nobody Tue Sep 29 06:47:01 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1DBA83CA49D for ; Tue, 11 Aug 2026 15:46:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463203; cv=none; b=ctkdVbdWgkTYM+UfhEyOuDge7VL1x3203Zknw68S522BWhd+JiWiqlc0nEOBcJa2TSN+onXTFNPlXAaRmrLm+iz/jYFF5/PH+bi7McuA2ISaFD0apdLWP3fw4PrBVnrU0JeAGZa+x+L4GsX/AMM0TVthV2XVsAqs+erBEx2ewQs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463203; c=relaxed/simple; bh=ex0ZLh6PKM9tufyYifIvVZQa8wH4ttTGPtURlhEQxuk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=tZWg2VhZK37xEeCn9tqbZJcZpfroNmAx7w2ytEwzg0vVUj3PvAEuDcLbKdb7FMjyuDTpcIu/cI5CiQUvGfc/xQtSYl0/25yJY5MZbr/trGoMyVqEU436xHVVDWpc0HYqi0nj1X47lxO9QPE/9K1gKg34H6Fevbmwd5HsD8b28p4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=ea9o8jHx; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="ea9o8jHx" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786463201; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=5a3EYPNVNlTBxGyC1VQCAo3aVVrthuP9CHEFYO6QRH8=; b=ea9o8jHxw5u/KIpi/0VS2GTtLD9AaxocxHMcpqON8rPqAvnFVxmnEilKfum+1E8HdL7FYq Os8DwcOujcftemuhoyx282L0hY7z9VpImuwCaA/6G4chIM82IAmOE/+i8ShbP1n4/GeBeI XNChZs0jbkK1qSlSb05NVwNuaX6KHTU= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-57-nNw22ZTIOWOZoqK6Az86pg-1; Tue, 11 Aug 2026 11:46:36 -0400 X-MC-Unique: nNw22ZTIOWOZoqK6Az86pg-1 X-Mimecast-MFC-AGG-ID: nNw22ZTIOWOZoqK6Az86pg_1786463195 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id DE79D1800578; Tue, 11 Aug 2026 15:46:34 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B5FCA3002D29; Tue, 11 Aug 2026 15:46:32 +0000 (UTC) From: Thomas Huth To: Namjae Jeon , Steve French Cc: linux-kernel@vger.kernel.org, Sergey Senozhatsky , Tom Talpey Subject: [PATCH v2 4/5] smb: server: Free sensitive data in connection.c with kfree_sensitive() Date: Tue, 11 Aug 2026 17:46:19 +0200 Message-ID: <20260811154620.2425851-5-thuth@redhat.com> In-Reply-To: <20260811154620.2425851-1-thuth@redhat.com> References: <20260811154620.2425851-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth struct ksmbd_conn contains an embedded struct ntlmssp_auth with the ciphertext[] and cryptkey[] arrays, so to avoid leaking this information via the heap, it should be freed with kfree_sensitive(). While we're at it, also use kfree_sensitive() for freeing preauth_info in ksmbd_conn_free() to avoid that the Preauth_HashValue[] could leak via the heap here, too. Signed-off-by: Thomas Huth --- fs/smb/server/connection.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/fs/smb/server/connection.c b/fs/smb/server/connection.c index ef6f202f4024c..68b9e698b1cb6 100644 --- a/fs/smb/server/connection.c +++ b/fs/smb/server/connection.c @@ -117,7 +117,7 @@ static void __ksmbd_conn_release_work(struct work_struc= t *work) =20 ida_destroy(&conn->async_ida); conn->transport->ops->free_transport(conn->transport); - kfree(conn); + kfree_sensitive(conn); } =20 /** @@ -183,7 +183,7 @@ void ksmbd_conn_free(struct ksmbd_conn *conn) */ xa_destroy(&conn->sessions); kvfree(conn->request_buf); - kfree(conn->preauth_info); + kfree_sensitive(conn->preauth_info); kfree(conn->mechToken); ksmbd_conn_put(conn); } @@ -671,7 +671,7 @@ static void stop_sessions(void) if (atomic_dec_and_test(&target->refcnt)) { ida_destroy(&target->async_ida); t->ops->free_transport(t); - kfree(target); + kfree_sensitive(target); } goto again; } --=20 2.55.0 From nobody Tue Sep 29 06:47:01 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EB2C13CC7DC for ; Tue, 11 Aug 2026 15:46:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463204; cv=none; b=SBDIDe7RUneA9MkxZ308R6knYl/MVD8w0sglSCTlERZEdG/u3XM44O2tDSYD/POBjdX6IFNfp1hTRmwqzkw9TsQ4p4KOc1b2kBfMFD5jvWhsX+h3JcBHMAhMAeCP2aNmmSxXYVLzwrCwkMSv++EUgzUbt/tCT1jmQKC/O75XNqo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786463204; c=relaxed/simple; bh=eSfNvzthlWvtJ69YZYrMhr/yehzd3iAe13DIW8iMPiA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XbToOF78+P0NYyMuwra//YetNX3DEwS983acaMeXf8Ec2+lhvucmZJebkp4vY6wWVSWYYIlUgaaYUax7A+LI9vNK6avSyV3e7H4TEbeLBk+xZI4vpYMplPjDxJNIXsFkJzn+saSkXHaXimRyF+4PX/QF5PdIHfGANEaRl5V67E8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=G271+u1k; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="G271+u1k" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786463201; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=FgISlfLGjn+UQ9H1W1zMKvHKz9IrVJ2M1jpg3ljKeGw=; b=G271+u1kw+UKXFphH/o4NxeTBQ03YIeJVlJroLYPAnHsml7OlvvadTBPCG/K6s1iPps0Rm bpUIwqlFUVXaBaahq2nGOrz0/K7+i9i/c9DR0qQY0A+XmipWAicYkLkGV+5AkGOnQW8hsg CFujXF9lg1dRVow2GqSPj4l4ffzTI3Q= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-529-53Yk6KYLNa2aBvOcochPeQ-1; Tue, 11 Aug 2026 11:46:38 -0400 X-MC-Unique: 53Yk6KYLNa2aBvOcochPeQ-1 X-Mimecast-MFC-AGG-ID: 53Yk6KYLNa2aBvOcochPeQ_1786463197 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5A0701800145; Tue, 11 Aug 2026 15:46:37 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 4BDBB3001DAF; Tue, 11 Aug 2026 15:46:35 +0000 (UTC) From: Thomas Huth To: Namjae Jeon , Steve French Cc: linux-kernel@vger.kernel.org, Sergey Senozhatsky , Tom Talpey Subject: [PATCH v2 5/5] smb: server: Clear Preauth_HashValue in smb2pdu.c with kfree_sensitive() Date: Tue, 11 Aug 2026 17:46:20 +0200 Message-ID: <20260811154620.2425851-6-thuth@redhat.com> In-Reply-To: <20260811154620.2425851-1-thuth@redhat.com> References: <20260811154620.2425851-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth struct preauth_session contains the Preauth_HashValue[] array that might contain sensitive data. Use kfree_sensitive() to clear it before returning the memory to the heap. Signed-off-by: Thomas Huth --- fs/smb/server/smb2pdu.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c index 184501e08b29a..fc44ac6b56427 100644 --- a/fs/smb/server/smb2pdu.c +++ b/fs/smb/server/smb2pdu.c @@ -2136,7 +2136,7 @@ int smb2_sess_setup(struct ksmbd_work *work) ksmbd_preauth_session_lookup(conn, sess->id); if (preauth_sess) { list_del(&preauth_sess->preauth_entry); - kfree(preauth_sess); + kfree_sensitive(preauth_sess); } } } else { @@ -2190,7 +2190,7 @@ int smb2_sess_setup(struct ksmbd_work *work) preauth_sess =3D ksmbd_preauth_session_lookup(conn, sess->id); if (preauth_sess) { list_del(&preauth_sess->preauth_entry); - kfree(preauth_sess); + kfree_sensitive(preauth_sess); } } =20 --=20 2.55.0