Skip to content

Commit a3d8374

Browse files
author
CKI Backport Bot
committed
cifs: Fix oops due to uninitialised variable
JIRA: https://issues.redhat.com/browse/RHEL-120561 CVE: CVE-2025-38737 commit 453a6d2 Author: David Howells <dhowells@redhat.com> Date: Tue Aug 19 16:27:36 2025 +0100 cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before calling netfs_alloc_folioq_buffer() as netfs assumes it can append to the buffer it is given. Setting it to NULL means it should start a fresh buffer, but the value is currently undefined. Fixes: a2906d3 ("cifs: Switch crypto buffer to use a folio_queue rather than an xarray") Signed-off-by: David Howells <dhowells@redhat.com> cc: Steve French <sfrench@samba.org> cc: Paulo Alcantara <pc@manguebit.org> cc: linux-cifs@vger.kernel.org cc: linux-fsdevel@vger.kernel.org Signed-off-by: Steve French <stfrench@microsoft.com> Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
1 parent 14c3cf9 commit a3d8374

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

fs/smb/client/smb2ops.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4487,7 +4487,7 @@ smb3_init_transform_rq(struct TCP_Server_Info *server, int num_rqst,
44874487
for (int i = 1; i < num_rqst; i++) {
44884488
struct smb_rqst *old = &old_rq[i - 1];
44894489
struct smb_rqst *new = &new_rq[i];
4490-
struct folio_queue *buffer;
4490+
struct folio_queue *buffer = NULL;
44914491
size_t size = iov_iter_count(&old->rq_iter);
44924492

44934493
orig_len += smb_rqst_len(server, old);

0 commit comments

Comments
 (0)