From nobody Tue Sep 29 04:39:03 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D187944838E for ; Wed, 12 Aug 2026 13:02:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539735; cv=none; b=el9ddOq5n2k6pDa7gImsa0vob9VAvK+tquV/5JWNNIMHcj4GFn0zcnw8HbHmTFU2BfF+YcekQCTilEH+KHYl9CNg1BTQaSl3BAzb/zr63K/qc8l6Ui1XZEJh2p0Lwt0B4h/xfMiLPINDG4fnNsRRFoteBdOvAfq3Dai8My6c0M8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539735; c=relaxed/simple; bh=YXjXrOgNFGzqvM4hsIdhJQXZmmZk6MzBeYRGbDaPGkA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PDNlZkl21KB2BmjbjOGr4lAHz77Yp19aDW3UI7sBiYM0kvDSBxLlKwx2qJv+t7lwGWfHXg4AP8mJQUitqTAsX0CgtxOOzB1c0cKLz9WE1Q0eG6HD9C3Re3xpcG0IaqGaXcB/hWm58iddA8MeFXLuHlbV7Ql84lSmTkxa+IkxIWQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=axtdG7yd; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="axtdG7yd" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786539732; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Z623CKv1hdADKFTYV+YYmA8vdXYt1jIoP/s4pA5BP4c=; b=axtdG7ydNqQFctV/kIWLpuiiisAc1FHbzJmM91LmlcFLscQW8qnMT4eUQeamLpzeEaHSkO JGCTN8OuHu5Z9QlIyJA3sc066Pwb8S70g2Kd6TlvHUhjvDCM5VMYr9Km4c/ZZsiYw5MB4K x2xMTCLudA+DzgycK8dFTKdxomoWhn4= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-628-qn4Nae7zMymS2uUA44O0kg-1; Wed, 12 Aug 2026 09:02:02 -0400 X-MC-Unique: qn4Nae7zMymS2uUA44O0kg-1 X-Mimecast-MFC-AGG-ID: qn4Nae7zMymS2uUA44O0kg_1786539720 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 701211800D9E; Wed, 12 Aug 2026 13:02:00 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DAD97195DF91; Wed, 12 Aug 2026 13:01:57 +0000 (UTC) From: Thomas Huth To: Steve French Cc: Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 1/5] smb: client: Clear sensitive stack data in smb2transport.c Date: Wed, 12 Aug 2026 15:01:48 +0200 Message-ID: <20260812130152.2861834-2-thuth@redhat.com> In-Reply-To: <20260812130152.2861834-1-thuth@redhat.com> References: <20260812130152.2861834-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Sensitive data like keys that are stored in stack-local arrays could be leaked via the stack to the calling functions. There is no known vulnerability for this right now, but it's good security style to explicitly zeroize this sensitive material as soon as possible to avoid that it could be exploited together with other bugs later. Signed-off-by: Thomas Huth --- fs/smb/client/smb2transport.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/fs/smb/client/smb2transport.c b/fs/smb/client/smb2transport.c index 1143ee52470a7..fdc634d99da03 100644 --- a/fs/smb/client/smb2transport.c +++ b/fs/smb/client/smb2transport.c @@ -249,6 +249,8 @@ smb2_calc_signature(struct smb_rqst *rqst, struct TCP_S= erver_Info *server) if (!rc) memcpy(shdr->Signature, smb2_signature, SMB2_SIGNATURE_SIZE); =20 + memzero_explicit(key, sizeof(key)); + memzero_explicit(&hmac_ctx, sizeof(hmac_ctx)); return rc; } =20 @@ -283,6 +285,7 @@ static void generate_key(struct cifs_ses *ses, struct k= vec label, hmac_sha256_final(&hmac_ctx, prfhash); =20 memcpy(key, prfhash, key_size); + memzero_explicit(prfhash, sizeof(prfhash)); } =20 struct derivation { @@ -482,6 +485,7 @@ smb3_calc_signature(struct smb_rqst *rqst, struct TCP_S= erver_Info *server) memset(shdr->Signature, 0x0, SMB2_SIGNATURE_SIZE); =20 rc =3D aes_cmac_preparekey(&cmac_key, key, SMB2_CMACAES_SIZE); + memzero_explicit(key, sizeof(key)); if (rc) { cifs_server_dbg(VFS, "%s: Could not set key for cmac aes\n", __func__); return rc; --=20 2.55.0 From nobody Tue Sep 29 04:39:03 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5BB8543B3FF for ; Wed, 12 Aug 2026 13:02:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539732; cv=none; b=s9pyyw7LI3mvn5SlrRtd8Xg8cG3u6D8FsWzzP/DrGqewYZm21wKW5l1D1fD8AbMFjo85IeAwJ3oxZnJc82XO0/3Tl3iE7t22rJSLRUcZnfrntpgivHiBNX1dX45dLj7SK1jEMa/lE8N3zmle3T2FXx0Y5lObF7uQTi7vnKaIwHE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539732; c=relaxed/simple; bh=ybWsysO1/ldrbMjwy4Ja+LI1+6iB7pNifJt1mUe1yP4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dy4Yo1eo5bQj3v62727Kbenr88xt964T79e7Tm2GIAGehDZHs8TON5l9iV6gVQg/1J2/HD+O2mrVyn2//jhDkUNoU7XWS949+qVqoloAyJuFCyAl0gKPGJ0VfduKm6xL6m4B1s58biwzlTnRd3KY0f33TsnCM/2ewBXreOW2UuY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=d54h4oz3; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="d54h4oz3" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786539730; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8a8VGNlPQgljRTJ9YZVx795VkCB4+m1vlXsh/HAygJo=; b=d54h4oz35Xh9eONNBgB2fYNmXOriQRrUtyYYbmujB/NiPQeOvm/E+ex/6qL8ocjHGHXv7h /ti6LdGJPRo2+IxqsNu42bIF2dWyphj3pCDimpA4B5w7gxBHrKgcJo73lV8j3GEsm9AbvG p7qDk5hMHA4Clj6/J8YPIfqv5880e4M= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-613-jxb2MRUTMwmOViYxJd9RNA-1; Wed, 12 Aug 2026 09:02:04 -0400 X-MC-Unique: jxb2MRUTMwmOViYxJd9RNA-1 X-Mimecast-MFC-AGG-ID: jxb2MRUTMwmOViYxJd9RNA_1786539723 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 66B981954B07; Wed, 12 Aug 2026 13:02:03 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1E221195DF9A; Wed, 12 Aug 2026 13:02:00 +0000 (UTC) From: Thomas Huth To: Steve French Cc: Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 2/5] smb: client: Clear sensitive stack and heap data in smb2ops.c Date: Wed, 12 Aug 2026 15:01:49 +0200 Message-ID: <20260812130152.2861834-3-thuth@redhat.com> In-Reply-To: <20260812130152.2861834-1-thuth@redhat.com> References: <20260812130152.2861834-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Make sure to not leak key-related data via the heap or the stack by using kfree_sensitive() or memzero_explicit() here. Signed-off-by: Thomas Huth --- fs/smb/client/smb2ops.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c index 192649fec25d5..a3099a0e5c2be 100644 --- a/fs/smb/client/smb2ops.c +++ b/fs/smb/client/smb2ops.c @@ -1569,7 +1569,7 @@ SMB2_request_res_key(const unsigned int xid, struct c= ifs_tcon *tcon, memcpy(pcchunk->SourceKey, res_key->ResumeKey, COPY_CHUNK_RES_KEY_SIZE); =20 req_res_key_exit: - kfree(res_key); + kfree_sensitive(res_key); return rc; } =20 @@ -4636,7 +4636,7 @@ crypt_message(struct TCP_Server_Info *server, int num= _rqst, rc =3D crypto_aead_setkey(tfm, key, SMB3_GCM256_CRYPTKEY_SIZE); else rc =3D crypto_aead_setkey(tfm, key, SMB3_GCM128_CRYPTKEY_SIZE); - + memzero_explicit(key, sizeof(key)); if (rc) { cifs_server_dbg(VFS, "%s: Failed to set aead key %d\n", __func__, rc); return rc; --=20 2.55.0 From nobody Tue Sep 29 04:39:03 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A77A3449B0A for ; Wed, 12 Aug 2026 13:02:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539739; cv=none; b=n4FOL8CgvbQNqbEhfOM8khbjiiPrjWlJfAOON+r3QNNmxWHpwsId1V09ZPwB4DyvibixSsJ7C0kSvYRxZVdNNyhTmLBHS+Nn5EOh4vi/7jLgX3cDQF35Z+o85ijgPWoO4AkGBoBDh6XSp9kraPjH+K6r00/eiWy91eKofLQEars= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539739; c=relaxed/simple; bh=37ZSvZMQ2O84LLv1NrrM4exFGYMoCZLXyaB0R0JKzLA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ZcUUXPvGnCfW13ZmIruMqkQYIop6pyry9o6d33ci7eLMO1A0S33JBJ1BFtjy4cTd7p8LQHiMPiCBI05HeDLRxxUSUZZkbhSP4CRtw/3HS1QoyCXduS4IuRIxJuMs2efUYMamQp6bz7UUC15ktutqzEZ694XxOsAj8Ae8/8KgMLw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=IkjwiH7M; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="IkjwiH7M" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786539736; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RvIJq3MUEqJM1jGf5uqldrBdTrF/LDQARguKWvHM3lw=; b=IkjwiH7Mxz+ikwsal8ZvCnf1XiknxOWW0lfk/Mwp+URW7cfZVh2twpiORLtJvfAatiVQeE Pjn77oJp++IhDfpBspTTYpn65+bny2705g6QJtnq2nER9Es/srle+1wNoSpNhudolyo+s5 QskrCVw/Nai740bh5a6sJ1+RubipZEI= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-354-v9kdM2k5O_y1MeNf7Ctwbw-1; Wed, 12 Aug 2026 09:02:08 -0400 X-MC-Unique: v9kdM2k5O_y1MeNf7Ctwbw-1 X-Mimecast-MFC-AGG-ID: v9kdM2k5O_y1MeNf7Ctwbw_1786539726 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 57AA6180034F; Wed, 12 Aug 2026 13:02:06 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D709C195DF91; Wed, 12 Aug 2026 13:02:03 +0000 (UTC) From: Thomas Huth To: Steve French Cc: Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 3/5] smb: client: Clear sensitive stack data in cifsencrypt.c Date: Wed, 12 Aug 2026 15:01:50 +0200 Message-ID: <20260812130152.2861834-4-thuth@redhat.com> In-Reply-To: <20260812130152.2861834-1-thuth@redhat.com> References: <20260812130152.2861834-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Make sure to not leak hash data via the stack, clear it with memzero_explicit() before leaving the function. Signed-off-by: Thomas Huth --- fs/smb/client/cifsencrypt.c | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/fs/smb/client/cifsencrypt.c b/fs/smb/client/cifsencrypt.c index 34804e9842a80..71a2a59123f57 100644 --- a/fs/smb/client/cifsencrypt.c +++ b/fs/smb/client/cifsencrypt.c @@ -249,12 +249,13 @@ static int calc_ntlmv2_hash(struct cifs_ses *ses, cha= r *ntlmv2_hash, E_md4hash(ses->password, nt_hash, nls_cp); =20 hmac_md5_init_usingrawkey(&hmac_ctx, nt_hash, CIFS_NTHASH_SIZE); + memzero_explicit(nt_hash, sizeof(nt_hash)); =20 /* convert ses->user_name to unicode */ len =3D ses->user_name ? strlen(ses->user_name) : 0; user =3D kmalloc(2 + (len * 2), GFP_KERNEL); if (user =3D=3D NULL) - return -ENOMEM; + goto out_nomem; =20 if (len) { len =3D cifs_strtoUTF16(user, ses->user_name, len, nls_cp); @@ -272,7 +273,7 @@ static int calc_ntlmv2_hash(struct cifs_ses *ses, char = *ntlmv2_hash, =20 domain =3D kmalloc(2 + (len * 2), GFP_KERNEL); if (domain =3D=3D NULL) - return -ENOMEM; + goto out_nomem; =20 len =3D cifs_strtoUTF16((__le16 *)domain, ses->domainName, len, nls_cp); @@ -284,7 +285,7 @@ static int calc_ntlmv2_hash(struct cifs_ses *ses, char = *ntlmv2_hash, =20 server =3D kmalloc(2 + (len * 2), GFP_KERNEL); if (server =3D=3D NULL) - return -ENOMEM; + goto out_nomem; =20 len =3D cifs_strtoUTF16((__le16 *)server, ses->ip_addr, len, nls_cp); hmac_md5_update(&hmac_ctx, (const u8 *)server, 2 * len); @@ -293,6 +294,10 @@ static int calc_ntlmv2_hash(struct cifs_ses *ses, char= *ntlmv2_hash, =20 hmac_md5_final(&hmac_ctx, ntlmv2_hash); return 0; + +out_nomem: + memzero_explicit(&hmac_ctx, sizeof(hmac_ctx)); + return -ENOMEM; } =20 static void CalcNTLMv2_response(const struct cifs_ses *ses, char *ntlmv2_h= ash) @@ -463,6 +468,7 @@ setup_ntlmv2_rsp(struct cifs_ses *ses, const struct nls= _table *nls_cp) rc =3D 0; unlock: cifs_server_unlock(ses->server); + memzero_explicit(ntlmv2_hash, sizeof(ntlmv2_hash)); setup_ntlmv2_rsp_ret: kfree_sensitive(tiblob); =20 --=20 2.55.0 From nobody Tue Sep 29 04:39:03 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 387A24499AA for ; Wed, 12 Aug 2026 13:02:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539737; cv=none; b=HJqjRwwKWgd4onmlN6HvQC7Llr+vHKlQTgheenW7cp33N2XFyAry6nLwG/V4GQ4JBubj2Cn9My2aoo91SRtmmlGVtF3S6PdvMBPDxULlhDr2mVyzWNF6FkYscXXgPuP3mr3CnbzUxcf2yaidaK9JupVCVWxjCLqIa2SqoCUMaGQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539737; c=relaxed/simple; bh=Ak8TRsQm8sEv91HLZDJ2c4Tbi82najZMuf991Ee04eo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=nNA26dMlkpGBVv3doDgFm7qmLCtMEpEP2n1qvPrTljC2L+0mODlSedt1MctBUR3pWm0Cx66+xegaESQ2jvq5C5BjiEIupINM5DNHYD81CiCoEvZqM5EMCY8Wps8uoLSjodZ3hBdrs+I+gRdhN4TOgJ8Cc4urH+oVMl1NIbJgd2E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=O+yl16H5; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="O+yl16H5" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786539735; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C4G9wA9sxztkPp9GXgL2r4jkSKN5/Us6P6aBbvPhsk8=; b=O+yl16H5LjLXUXeWN2kA/GuLIexeMxLd8rMnHDVXvdyb8wD+Kg9a9SqArHqPRAYiemTTlC ostVKbN1m5cQ+rfuzQ8ub1rnoX5MJaU3Onr2LZ+cefWvNqS7S1Os86KzcuPM+4+Oqsbafk Bm7qnAG+AV9ZyDscMnA1bunsPiI0KkE= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-522-8ZbhZGt2PBKLUKZOKg6AKQ-1; Wed, 12 Aug 2026 09:02:11 -0400 X-MC-Unique: 8ZbhZGt2PBKLUKZOKg6AKQ-1 X-Mimecast-MFC-AGG-ID: 8ZbhZGt2PBKLUKZOKg6AKQ_1786539729 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8CC3618007FD; Wed, 12 Aug 2026 13:02:09 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E17E1195DF91; Wed, 12 Aug 2026 13:02:06 +0000 (UTC) From: Thomas Huth To: Steve French Cc: Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 4/5] smb: client: Clear sensitive stack data in smb1encrypt.c Date: Wed, 12 Aug 2026 15:01:51 +0200 Message-ID: <20260812130152.2861834-5-thuth@redhat.com> In-Reply-To: <20260812130152.2861834-1-thuth@redhat.com> References: <20260812130152.2861834-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Make sure to not leak signature data via the stack, clear it with memzero_explicit() before leaving the function. To avoid that we have to introduce "goto"-cleanup here, we re-arrange the code a little bit (and drop the commented cifs_dump_mem debug code that looks like a leftover from very early days). Signed-off-by: Thomas Huth --- fs/smb/client/smb1encrypt.c | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/fs/smb/client/smb1encrypt.c b/fs/smb/client/smb1encrypt.c index bf10fdeeedcab..c9eb68f04e7b0 100644 --- a/fs/smb/client/smb1encrypt.c +++ b/fs/smb/client/smb1encrypt.c @@ -81,6 +81,7 @@ int cifs_sign_rqst(struct smb_rqst *rqst, struct TCP_Serv= er_Info *server, else memcpy(cifs_pdu->Signature.SecuritySignature, smb_signature, 8); =20 + memzero_explicit(smb_signature, sizeof(smb_signature)); return rc; } =20 @@ -126,15 +127,13 @@ int cifs_verify_signature(struct smb_rqst *rqst, rc =3D cifs_calc_signature(rqst, server, what_we_think_sig_should_be); cifs_server_unlock(server); =20 - if (rc) - return rc; - -/* cifs_dump_mem("what we think it should be: ", - what_we_think_sig_should_be, 16); */ - - if (crypto_memneq(server_response_sig, what_we_think_sig_should_be, 8)) - return -EACCES; - else - return 0; + if (!rc) { + if (crypto_memneq(server_response_sig, + what_we_think_sig_should_be, 8)) + rc =3D -EACCES; + } =20 + memzero_explicit(what_we_think_sig_should_be, + sizeof(what_we_think_sig_should_be)); + return rc; } --=20 2.55.0 From nobody Tue Sep 29 04:39:03 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D607D449B35 for ; Wed, 12 Aug 2026 13:02:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539740; cv=none; b=Nt4WMrFJTDCeunt5F7AwqCdHouZno5Jx9f/3Mj8rPxxpP7zRZ/9jWstvCzcpoEcqqB9XH8Q09QAlG75+5DaG5OHF5zMW+J7mZCyXHQKjEzWgqSGkb08MLT5yPdFqikNylRtO9i4ZxdN9mxG5Ri+NtUPc9bMpsHNF8+IXUjI73M8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786539740; c=relaxed/simple; bh=DvnegeIrv6OKOPiHrXojj6LcsSY3WCVv03dvXayuoa0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iypFys20veLXeZ9ooD1Swet4zqLPVYXkA3JPx8iaca6nidVUwnmfLqsW0jb8v/0hBmlLxMA+m0DYGDp2muL6DI98BtPkFT9LawSbj+DRUicyTOr1P/CdGn5tOjojf8qA6FNUBxekBCq0y8nwdd9h73ywHdf5mKl35Dqfm3IXK2Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=EjR2b0LC; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="EjR2b0LC" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786539737; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=xmRZHJXqO4JoOnDlM4sZvDjttBJFD86ZhVfCRofRcjE=; b=EjR2b0LC1aY9fKgxAE4sV6rtVYd+m+/oSZsyTLQjYduZw9C2agIYgn3jCJA0oCBPPcw84B wfprFwNdk2kDRhKcVsmOL9hOa6YQLrQAjQdM764MAXgxSJd65ts/jYqSUXokXgfnchAkTk tz+czno3YUKoTwBxMJNpDwp0pcVs7R0= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-654-tq2pPfS2MkmbLGo145cStA-1; Wed, 12 Aug 2026 09:02:14 -0400 X-MC-Unique: tq2pPfS2MkmbLGo145cStA-1 X-Mimecast-MFC-AGG-ID: tq2pPfS2MkmbLGo145cStA_1786539733 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 18DDC1954B08; Wed, 12 Aug 2026 13:02:13 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3A5FB195DF96; Wed, 12 Aug 2026 13:02:09 +0000 (UTC) From: Thomas Huth To: Steve French Cc: Paulo Alcantara , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 5/5] smb: client: Avoid leaking sensitive data to the heap in connect.c Date: Wed, 12 Aug 2026 15:01:52 +0200 Message-ID: <20260812130152.2861834-6-thuth@redhat.com> In-Reply-To: <20260812130152.2861834-1-thuth@redhat.com> References: <20260812130152.2861834-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth TCP_Server_Info contains a preauth_sha_hash[] and a cryptkey[] array that might contain sensitive data. Thus free its memory with kfree_sensitive() to avoid that we are leaking this information to the heap. Signed-off-by: Thomas Huth --- fs/smb/client/connect.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/smb/client/connect.c b/fs/smb/client/connect.c index ba749ec25a59f..5675d7fc2c818 100644 --- a/fs/smb/client/connect.c +++ b/fs/smb/client/connect.c @@ -1143,7 +1143,7 @@ clean_demultiplex_info(struct TCP_Server_Info *server) put_net(cifs_net_ns(server)); kfree(server->leaf_fullpath); kfree(server->hostname); - kfree(server); + kfree_sensitive(server); =20 length =3D atomic_dec_return(&tcpSesAllocCount); if (length > 0) --=20 2.55.0