From nobody Sat Sep 26 09:19:24 2026 Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2F2F3374186 for ; Wed, 2 Sep 2026 18:28:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788373706; cv=none; b=A7FQsSlrKfmoKo+K2831hl7hsAmft8pkcnYt43AdcMR2gUhQIoVxmxxOnBfGlQKqb09Vd7uRRlIo7O64+8blsXxrMbvdHkOiv9c45QH6HdZ7aub86FUZy/uyS3NRL5mVZVbvcvo+++oav+QI3qORqLI1wARxs93jjZO4DSeZZ8I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788373706; c=relaxed/simple; bh=IoD8kxRSKBVmpHH9Yga6lz2dzGvZpGp7jqYOG/7TR1s=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=rsVPPQjUs37XQO/vc3J4pBq2cgilnBOq4mGw2zXCbBmKLPWJQkoPBzt8RKHjMtb5A2LA69DEI4ZsGnkppWkdNjspMaGAyV2+BuVSdNYgQZlNHoCVvbUl+rdlxRAsjFHZJGyojRb7pMq1tZOeXTptuacwBV2iaGnMv8CkBR4XIFY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=p1ARZDsA; arc=none smtp.client-ip=209.85.128.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="p1ARZDsA" Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-499b2981a7bso14542165e9.3 for ; Wed, 02 Sep 2026 11:28:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788373701; x=1788978501; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=5XR27vgN5nJ/lgsOm3NqnEQEtuojTb2G48lFGrn17tw=; b=p1ARZDsAE1KZAvr9IyAGs028f0GWghab2sjeK0vZfDibUPZweloLt6RTQO/7pVK8pI SKYBBHxs9QNi2Nfc1lpUXPHnVTglt+dqq4/GQELiT5CYguw6APmgxAXHRhzrVdDJ768l fjWx3Og8SStLnXQzBOZ2W/TtcB/KLeqgWYFIMww55OEOI2fH2B3+khzwe0HUFBz4jxA9 PjMwVf0kEqYkDs/pcs4Q5AygS4UCOdRRX/Hc9jibskOny9kHZsKHD5uOWas0GOYKMuW0 +q+khibAsjRX3QuIMC5eLZ3gNJQQlQTvxhVwxX4kJCZfNziuss5aIQ6ndoIweVYuPv/S JBrA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788373701; x=1788978501; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5XR27vgN5nJ/lgsOm3NqnEQEtuojTb2G48lFGrn17tw=; b=F8ftvnezQLElwf4mqIDaBVm5G4q1VV5WzUyocqJjBzXUbTIdi5V+5IByUcyXypJKuC 1KaY1cg851/5G62CZ57aQvM8W1bLusgJ7olwRY57Zbe6UIZrTeQwi3uYVRNcAnemFDOW 9X0X18qeAOHnFiYbcMs8GMH9p/ApWXGhiANFSz9m8nQxjBKBX9Svm4sVcECXGJFfLD7K OxLqAybjh4IwG2yOyyJgvPZj2KBVz+zwgvcpf64QUfC9Yq4Z2M+pNmU/L4LUx3mlmAD4 785l8GCVnPj72sK2UWt15n5JMo+01fZv0geeg16ISuttR0KgUrmi34fgVXb/9s6P+xD0 rCTA== X-Forwarded-Encrypted: i=1; AKwUvBxOfOWC3Cr2zSO9lN6GrTAvzQhCPVdnotq7HVxIRKawTdeuCVTOUyJIdDZ0TCN4yb7gxJasqm+NLa4JXBE=@vger.kernel.org X-Gm-Message-State: AFuF++m1gWdShG3pjhqtsEfUYGj2fNNDfcogTtqMMZTq/BtClOSYvO3k +icmpvdr+LewXWy/4SlsVUq4yfZn9XxxZBW9wPVNGycppHP0Qac5HJOa X-Gm-Gg: AYBFou1/AoV0iX8PRkiLmM+4lRmEB/JlZm/FY0e0kHSFZbHb36+zxYnEp+IBcdYSWVv NCvCXNjlgtXnrFSOZMGlofdY44qvMrzsRnfdjJScDFx7XDfzTbJewPshJ8Ddy9bjWfwIc6bXYm0 zlFKv6xj7S0lgNPjwhvgfm7InbNEUeDCJhlpWJ+Rl8bcuDjRIquPI/gIwskLXZhdCGdvS8k3Gsl VHWffOoq7pjabChmJK32ir0b0wqtaP+3Xtbu6rAl+gBGVDingM4n1NdE2DR/Oof0CetZ1nG+3Q0 GoQU0IzgUM4Yb16PnZwgUvHYo9IZQCDZNWHOxcgCQFqNH30RmLL+MG/Fz4PrgNg63AiNO6fzGxC 51CiI613J+CurMPTqzSdiwWAHSfvROK6pudz9/5Lv8obI/bhbjSvNM7fyP3earLVbLhuP6SLJs7 Y/JNLDBFa5uT3qLBoCr6V6YjxsYtBBHTc9rs9WnOShaaIAxlZ1Z26QHjGJKFYjYfzB7uFrABGuv 33V19tV1TMkWOn+wfYJQWuR39ehtAR4g4ThnZ7IZJn/qonmShCi62hlIegC24cJ1a4qmWAaB2yz ckDT3Alawcr6olT8ndmmHeabkRXqqLaYm4RkkSfgDngrh0XLzQZrBlAy4Bq3HjiI+w== X-Received: by 2002:a05:600c:83c8:b0:49c:d52e:d0ea with SMTP id 5b1f17b1804b1-49ce581779dmr132214455e9.4.1788373700879; Wed, 02 Sep 2026 11:28:20 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-a1c2-c401-11b2-c123-0d12-6c0f.310.pool.telefonica.de. [2a02:3100:a1c2:c401:11b2:c123:d12:6c0f]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cee5dea34sm10208755e9.10.2026.09.02.11.28.19 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 02 Sep 2026 11:28:19 -0700 (PDT) From: Karl Mehltretter To: Paulo Alcantara , Namjae Jeon Cc: Karl Mehltretter , Ronnie Sahlberg , Shyam Prasad N , Tom Talpey , Bharath SM , linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org Subject: [PATCH] smb: client: pin DFS superblock in iterator callback Date: Wed, 2 Sep 2026 20:28:14 +0200 Message-Id: <20260902182814.25700-1-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" tcon_super_cb() stores a raw superblock pointer, but __cifs_get_super() takes its active reference only after iterate_supers_type() has dropped s_umount and its passive reference. Concurrent DFS automount expiry can therefore free the superblock before cifs_sb_active() uses it. A deterministic KASAN test reproduces the race as: BUG: KASAN: slab-use-after-free in cifs_sb_active+0x77/0x80 The same test passes with this change applied. Take the active reference in the callback while iterate_supers_type() still holds s_umount shared. cifs_put_tcp_super() remains the matching release. Fixes: bacd704a95ad ("cifs: handle prefix paths in reconnect") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Karl Mehltretter --- Testing: x86_64 QEMU KASAN A/B with deterministic KUnit synchronization around the lifetime gap and real VFS superblock allocation/teardown. Baseline reports a slab-use-after-free in cifs_sb_active(); fixed passes. fs/smb/client/misc.c | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/fs/smb/client/misc.c b/fs/smb/client/misc.c index 46e1382e8e04b..d4db3f91a91fa 100644 --- a/fs/smb/client/misc.c +++ b/fs/smb/client/misc.c @@ -891,8 +891,14 @@ static void tcon_super_cb(struct super_block *sb, void= *arg) t1->ses->dfs_root_ses =3D=3D t2->ses->dfs_root_ses) && t1->ses->server =3D=3D t2->ses->server && t2->origin_fullpath && - dfs_src_pathname_equal(t2->origin_fullpath, t1->origin_fullpath)) + dfs_src_pathname_equal(t2->origin_fullpath, t1->origin_fullpath)) { + /* + * Take the active reference while iterate_supers_type() still + * holds s_umount shared. + */ + cifs_sb_active(sb); sd->sb =3D sb; + } spin_unlock(&t2->tc_lock); } =20 @@ -909,15 +915,8 @@ static struct super_block *__cifs_get_super(void (*f)(= struct super_block *, void =20 for (; *fs_type; fs_type++) { iterate_supers_type(*fs_type, f, &sd); - if (sd.sb) { - /* - * Grab an active reference in order to prevent automounts (DFS links) - * of expiring and then freeing up our cifs superblock pointer while - * we're doing failover. - */ - cifs_sb_active(sd.sb); + if (sd.sb) return sd.sb; - } } pr_warn_once("%s: could not find dfs superblock\n", __func__); return ERR_PTR(-EINVAL); --=20 2.53.0