{"api_version":"1","generated_at":"2026-09-30T23:26:54+00:00","cve":"CVE-2026-90174","urls":{"html":"https://cve.report/CVE-2026-90174","api":"https://cve.report/api/cve/CVE-2026-90174.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90174","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90174"},"summary":{"title":"ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()\n\nksmbd_alloc_user() copies resp->hash_sz bytes out of the mountd IPC\nlogin response with\n\n\tuser->passkey_sz = resp->hash_sz;\n\tuser->passkey = kmalloc(resp->hash_sz, KSMBD_DEFAULT_GFP);\n\tif (user->passkey)\n\t\tmemcpy(user->passkey, resp->hash, resp->hash_sz);\n\nresp->hash_sz is a __u16 supplied by the response, but resp->hash[] is\nonly KSMBD_REQ_MAX_HASH_SZ bytes.  A malformed or malicious login\nresponse can set hash_sz well beyond that (up to 65535), so the memcpy()\nreads past the end of the response object.  ipc_validate_msg() does not\nbound hash_sz, so reject any response whose hash_sz exceeds the on-stack\nhash[] buffer before allocating and copying.\n\n[ 2030.238706] BUG: KASAN: slab-out-of-bounds in ksmbd_alloc_user+0x278/0x680\n[ 2030.240549] Read of size 65535 at addr ffff888121bb6680 by task kworker/4:1/18611\n[ 2030.242296]\n[ 2030.242710] CPU: 4 UID: 0 PID: 18611 Comm: kworker/4:1 Not tainted 7.1.0-next-20260623-virtme #96 PREEMPT(lazy)\n[ 2030.242732] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n[ 2030.242743] Workqueue: ksmbd-io handle_ksmbd_work\n[ 2030.242763] Call Trace:\n[ 2030.242769]  <TASK>\n[ 2030.242776]  dump_stack_lvl+0xa2/0xd0\n[ 2030.242794]  print_address_description+0x77/0x200\n[ 2030.242815]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242831]  print_report+0x58/0x70\n[ 2030.242848]  kasan_report+0x117/0x150\n[ 2030.242869]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242888]  kasan_check_range+0x3c7/0x3f0\n[ 2030.242908]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242925]  __asan_memcpy+0x29/0x70\n[ 2030.242942]  ksmbd_alloc_user+0x278/0x680\n[ 2030.242960]  ksmbd_login_user+0xc3/0x120\n[ 2030.242978]  ntlm_authenticate+0x5e6/0x1b00\n[ 2030.243017]  ? __pfx_ntlm_authenticate+0x10/0x10\n[ 2030.243035]  ? ksmbd_session_lookup+0x188/0x1d0\n[ 2030.243054]  ? __pfx_ksmbd_session_lookup+0x10/0x10\n[ 2030.243090]  ? __sanitizer_cov_trace_switch+0x7b/0x140\n[ 2030.243108]  smb2_sess_setup+0x1e4a/0x27b0\n[ 2030.243126]  ? copy_from_kernel_nofault+0x199/0x300\n[ 2030.243156]  ? __pfx_smb2_sess_setup+0x10/0x10\n[ 2030.243173]  ? get_smb2_cmd_val+0xe3/0x1c0\n[ 2030.243208]  handle_ksmbd_work+0x954/0x1280\n[ 2030.243230]  ? __pfx_handle_ksmbd_work+0x10/0x10\n[ 2030.243249]  ? process_scheduled_works+0xa07/0x1490\n[ 2030.243270]  ? process_scheduled_works+0xa07/0x1490\n[ 2030.243291]  process_scheduled_works+0xa70/0x1490\n[ 2030.243320]  ? __pfx_process_scheduled_works+0x10/0x10\n[ 2030.243340]  ? do_raw_spin_lock+0x130/0x300\n[ 2030.243358]  ? lock_is_held_type+0x7b/0x110\n[ 2030.243388]  worker_thread+0x932/0xe20\n[ 2030.243415]  kthread+0x38a/0x470\n[ 2030.243431]  ? __pfx_worker_thread+0x10/0x10\n[ 2030.243451]  ? __pfx_kthread+0x10/0x10\n[ 2030.243467]  ret_from_fork+0x484/0x910\n[ 2030.243485]  ? __pfx_ret_from_fork+0x10/0x10\n[ 2030.243501]  ? __switch_to+0xc77/0x12c0\n[ 2030.243523]  ? __pfx_kthread+0x10/0x10\n[ 2030.243540]  ret_from_fork_asm+0x1a/0x30\n[ 2030.243564]  </TASK>\n[ 2030.243570]\n[ 2030.290164] Allocated by task 19279:\n[ 2030.290911]  kasan_save_track+0x3e/0x80\n[ 2030.292179]  __kasan_kmalloc+0x72/0x90\n[ 2030.293217]  __kvmalloc_node_noprof+0x3ff/0x6b0\n[ 2030.294467]  handle_generic_event+0x59b/0x750\n[ 2030.295345]  genl_family_rcv_msg_doit+0x238/0x340\n[ 2030.296553]  genl_rcv_msg+0x606/0x7b0\n[ 2030.297129]  netlink_rcv_skb+0x22b/0x4a0\n[ 2030.298500]  genl_rcv+0x2d/0x40\n[ 2030.299273]  netlink_unicast+0x7ba/0x930\n[ 2030.300019]  netlink_sendmsg+0x8c3/0xb00\n[ 2030.301073]  __sock_sendmsg+0xec/0x140\n[ 2030.301579]  __sys_sendto+0x357/0x470\n[ 2030.302255]  __x64_sys_sendto+0xe3/0x100\n[ 2030.303425]  do_syscall_64+0x135/0x460\n[ 2030.304763]  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 2030.305594]\n[ 2030.305819] The buggy address belongs to the object at ffff888121bb6640\n[ 2030.305819]  which belongs to the cache kmalloc-192 of size 192\n[ 2030.309595] The buggy address \n---truncated---","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:11","updated_at":"2026-09-18 18:17:45"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/497c221bf6b2f659511719a6acfae84cc1be1caf","name":"https://git.kernel.org/stable/c/497c221bf6b2f659511719a6acfae84cc1be1caf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7405d0ba294306721843bc551611775e6edef516","name":"https://git.kernel.org/stable/c/7405d0ba294306721843bc551611775e6edef516","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90174","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90174","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 497c221bf6b2f659511719a6acfae84cc1be1caf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 7405d0ba294306721843bc551611775e6edef516 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90174","cve":"CVE-2026-90174","epss":"0.001500000","percentile":"0.045260000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/smb/server/mgmt/user_config.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"497c221bf6b2f659511719a6acfae84cc1be1caf","status":"affected","version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","versionType":"git"},{"lessThan":"7405d0ba294306721843bc551611775e6edef516","status":"affected","version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/smb/server/mgmt/user_config.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.15"},{"lessThan":"5.15","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"5.15","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()\n\nksmbd_alloc_user() copies resp->hash_sz bytes out of the mountd IPC\nlogin response with\n\n\tuser->passkey_sz = resp->hash_sz;\n\tuser->passkey = kmalloc(resp->hash_sz, KSMBD_DEFAULT_GFP);\n\tif (user->passkey)\n\t\tmemcpy(user->passkey, resp->hash, resp->hash_sz);\n\nresp->hash_sz is a __u16 supplied by the response, but resp->hash[] is\nonly KSMBD_REQ_MAX_HASH_SZ bytes.  A malformed or malicious login\nresponse can set hash_sz well beyond that (up to 65535), so the memcpy()\nreads past the end of the response object.  ipc_validate_msg() does not\nbound hash_sz, so reject any response whose hash_sz exceeds the on-stack\nhash[] buffer before allocating and copying.\n\n[ 2030.238706] BUG: KASAN: slab-out-of-bounds in ksmbd_alloc_user+0x278/0x680\n[ 2030.240549] Read of size 65535 at addr ffff888121bb6680 by task kworker/4:1/18611\n[ 2030.242296]\n[ 2030.242710] CPU: 4 UID: 0 PID: 18611 Comm: kworker/4:1 Not tainted 7.1.0-next-20260623-virtme #96 PREEMPT(lazy)\n[ 2030.242732] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n[ 2030.242743] Workqueue: ksmbd-io handle_ksmbd_work\n[ 2030.242763] Call Trace:\n[ 2030.242769]  <TASK>\n[ 2030.242776]  dump_stack_lvl+0xa2/0xd0\n[ 2030.242794]  print_address_description+0x77/0x200\n[ 2030.242815]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242831]  print_report+0x58/0x70\n[ 2030.242848]  kasan_report+0x117/0x150\n[ 2030.242869]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242888]  kasan_check_range+0x3c7/0x3f0\n[ 2030.242908]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242925]  __asan_memcpy+0x29/0x70\n[ 2030.242942]  ksmbd_alloc_user+0x278/0x680\n[ 2030.242960]  ksmbd_login_user+0xc3/0x120\n[ 2030.242978]  ntlm_authenticate+0x5e6/0x1b00\n[ 2030.243017]  ? __pfx_ntlm_authenticate+0x10/0x10\n[ 2030.243035]  ? ksmbd_session_lookup+0x188/0x1d0\n[ 2030.243054]  ? __pfx_ksmbd_session_lookup+0x10/0x10\n[ 2030.243090]  ? __sanitizer_cov_trace_switch+0x7b/0x140\n[ 2030.243108]  smb2_sess_setup+0x1e4a/0x27b0\n[ 2030.243126]  ? copy_from_kernel_nofault+0x199/0x300\n[ 2030.243156]  ? __pfx_smb2_sess_setup+0x10/0x10\n[ 2030.243173]  ? get_smb2_cmd_val+0xe3/0x1c0\n[ 2030.243208]  handle_ksmbd_work+0x954/0x1280\n[ 2030.243230]  ? __pfx_handle_ksmbd_work+0x10/0x10\n[ 2030.243249]  ? process_scheduled_works+0xa07/0x1490\n[ 2030.243270]  ? process_scheduled_works+0xa07/0x1490\n[ 2030.243291]  process_scheduled_works+0xa70/0x1490\n[ 2030.243320]  ? __pfx_process_scheduled_works+0x10/0x10\n[ 2030.243340]  ? do_raw_spin_lock+0x130/0x300\n[ 2030.243358]  ? lock_is_held_type+0x7b/0x110\n[ 2030.243388]  worker_thread+0x932/0xe20\n[ 2030.243415]  kthread+0x38a/0x470\n[ 2030.243431]  ? __pfx_worker_thread+0x10/0x10\n[ 2030.243451]  ? __pfx_kthread+0x10/0x10\n[ 2030.243467]  ret_from_fork+0x484/0x910\n[ 2030.243485]  ? __pfx_ret_from_fork+0x10/0x10\n[ 2030.243501]  ? __switch_to+0xc77/0x12c0\n[ 2030.243523]  ? __pfx_kthread+0x10/0x10\n[ 2030.243540]  ret_from_fork_asm+0x1a/0x30\n[ 2030.243564]  </TASK>\n[ 2030.243570]\n[ 2030.290164] Allocated by task 19279:\n[ 2030.290911]  kasan_save_track+0x3e/0x80\n[ 2030.292179]  __kasan_kmalloc+0x72/0x90\n[ 2030.293217]  __kvmalloc_node_noprof+0x3ff/0x6b0\n[ 2030.294467]  handle_generic_event+0x59b/0x750\n[ 2030.295345]  genl_family_rcv_msg_doit+0x238/0x340\n[ 2030.296553]  genl_rcv_msg+0x606/0x7b0\n[ 2030.297129]  netlink_rcv_skb+0x22b/0x4a0\n[ 2030.298500]  genl_rcv+0x2d/0x40\n[ 2030.299273]  netlink_unicast+0x7ba/0x930\n[ 2030.300019]  netlink_sendmsg+0x8c3/0xb00\n[ 2030.301073]  __sock_sendmsg+0xec/0x140\n[ 2030.301579]  __sys_sendto+0x357/0x470\n[ 2030.302255]  __x64_sys_sendto+0xe3/0x100\n[ 2030.303425]  do_syscall_64+0x135/0x460\n[ 2030.304763]  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 2030.305594]\n[ 2030.305819] The buggy address belongs to the object at ffff888121bb6640\n[ 2030.305819]  which belongs to the cache kmalloc-192 of size 192\n[ 2030.309595] The buggy address \n---truncated---"}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - ksmbd_alloc_user() memcpy()s resp->hash_sz bytes from resp->hash, and that __u16 is a field of the KSMBD_EVENT_LOGIN_RESPONSE copied in handle_generic_event() from a local SMBD_GENL netlink message. SMB2 SESSION_SETUP (smb2_sess_setup → ntlm_authenticate → ksmbd_login_user) only supplies the account name that queues ksmbd_ipc_login_request(); it does not carry hash_sz.\nAC:L - The sender sets hash_sz to any __u16 (up to 65535) in a sizeof(ksmbd_login_response) LOGIN_RESPONSE; ipc_validate_msg() has no KSMBD_EVENT_LOGIN_REQUEST case so it never bounds hash_sz. A matching ipc_ida handle is obtained by sending SESSION_SETUP and answering within the 2s IPC wait, with no uncontrolled race.\nPR:L - handle_generic_event() for KSMBD_EVENT_LOGIN_RESPONSE checks netlink_capable(CAP_NET_ADMIN) only when CONFIG_SMB_SERVER_CHECK_CAP_NET_ADMIN is set; ksmbd_genl_family is netnsok, the ops lack GENL_ADMIN_PERM, and LOGIN_RESPONSE is not bound to ksmbd_tools_pid. CAP_NET_ADMIN is Low, and builds that disable the check let any local user send it.\nUI:N - The attacker can connect to the local ksmbd TCP listener, send SMB2 SESSION_SETUP so ksmbd_ipc_login_request() waits on the handle, and inject the crafted LOGIN_RESPONSE themselves. No other user must log in or otherwise act once ksmbd is running.\nS:U - The slab over-read in ksmbd_alloc_user() and any oops of the ksmbd-io worker stay inside the host kernel that runs the SMB server. This is not a VM escape, IOMMU/DMA bypass, or other cross-authority impact.\nC:H - memcpy(user->passkey, resp->hash, resp->hash_sz) copies up to 65535 bytes from the 18-byte hash[] (KSMBD_REQ_MAX_HASH_SZ) of a packed ksmbd_login_response into kmalloc(hash_sz), which is an unbounded kernel-heap over-read rather than a few bounded bytes.\nI:N - kmalloc(resp->hash_sz) sizes the destination to the copy length, so the memcpy is a slab-out-of-bounds read with no OOB write. The LOGIN_RESPONSE sender already supplies uid/gid/account/status without this bug, and NTLM (calc_ntlmv2_hash) only consumes CIFS_ENCPWD_SIZE of passkey.\nA:H - A 65535-byte read from a kmalloc-192 LOGIN_RESPONSE object walks off the slab into unmapped memory and oopses the ksmbd-io worker, matching the KASAN report in ksmbd_alloc_user(). The attacker can repeat SESSION_SETUP plus a crafted LOGIN_RESPONSE to crash the kernel at will."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:53:34.788Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/497c221bf6b2f659511719a6acfae84cc1be1caf"},{"url":"https://git.kernel.org/stable/c/7405d0ba294306721843bc551611775e6edef516"}],"title":"ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90174","datePublished":"2026-09-17T16:07:01.106Z","dateReserved":"2026-09-11T19:38:34.791Z","dateUpdated":"2026-09-18T17:53:34.788Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:11","lastModifiedDate":"2026-09-18 18:17:45","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90174","Ordinal":"1","Title":"ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()","CVE":"CVE-2026-90174","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90174","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()\n\nksmbd_alloc_user() copies resp->hash_sz bytes out of the mountd IPC\nlogin response with\n\n\tuser->passkey_sz = resp->hash_sz;\n\tuser->passkey = kmalloc(resp->hash_sz, KSMBD_DEFAULT_GFP);\n\tif (user->passkey)\n\t\tmemcpy(user->passkey, resp->hash, resp->hash_sz);\n\nresp->hash_sz is a __u16 supplied by the response, but resp->hash[] is\nonly KSMBD_REQ_MAX_HASH_SZ bytes.  A malformed or malicious login\nresponse can set hash_sz well beyond that (up to 65535), so the memcpy()\nreads past the end of the response object.  ipc_validate_msg() does not\nbound hash_sz, so reject any response whose hash_sz exceeds the on-stack\nhash[] buffer before allocating and copying.\n\n[ 2030.238706] BUG: KASAN: slab-out-of-bounds in ksmbd_alloc_user+0x278/0x680\n[ 2030.240549] Read of size 65535 at addr ffff888121bb6680 by task kworker/4:1/18611\n[ 2030.242296]\n[ 2030.242710] CPU: 4 UID: 0 PID: 18611 Comm: kworker/4:1 Not tainted 7.1.0-next-20260623-virtme #96 PREEMPT(lazy)\n[ 2030.242732] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n[ 2030.242743] Workqueue: ksmbd-io handle_ksmbd_work\n[ 2030.242763] Call Trace:\n[ 2030.242769]  <TASK>\n[ 2030.242776]  dump_stack_lvl+0xa2/0xd0\n[ 2030.242794]  print_address_description+0x77/0x200\n[ 2030.242815]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242831]  print_report+0x58/0x70\n[ 2030.242848]  kasan_report+0x117/0x150\n[ 2030.242869]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242888]  kasan_check_range+0x3c7/0x3f0\n[ 2030.242908]  ? ksmbd_alloc_user+0x278/0x680\n[ 2030.242925]  __asan_memcpy+0x29/0x70\n[ 2030.242942]  ksmbd_alloc_user+0x278/0x680\n[ 2030.242960]  ksmbd_login_user+0xc3/0x120\n[ 2030.242978]  ntlm_authenticate+0x5e6/0x1b00\n[ 2030.243017]  ? __pfx_ntlm_authenticate+0x10/0x10\n[ 2030.243035]  ? ksmbd_session_lookup+0x188/0x1d0\n[ 2030.243054]  ? __pfx_ksmbd_session_lookup+0x10/0x10\n[ 2030.243090]  ? __sanitizer_cov_trace_switch+0x7b/0x140\n[ 2030.243108]  smb2_sess_setup+0x1e4a/0x27b0\n[ 2030.243126]  ? copy_from_kernel_nofault+0x199/0x300\n[ 2030.243156]  ? __pfx_smb2_sess_setup+0x10/0x10\n[ 2030.243173]  ? get_smb2_cmd_val+0xe3/0x1c0\n[ 2030.243208]  handle_ksmbd_work+0x954/0x1280\n[ 2030.243230]  ? __pfx_handle_ksmbd_work+0x10/0x10\n[ 2030.243249]  ? process_scheduled_works+0xa07/0x1490\n[ 2030.243270]  ? process_scheduled_works+0xa07/0x1490\n[ 2030.243291]  process_scheduled_works+0xa70/0x1490\n[ 2030.243320]  ? __pfx_process_scheduled_works+0x10/0x10\n[ 2030.243340]  ? do_raw_spin_lock+0x130/0x300\n[ 2030.243358]  ? lock_is_held_type+0x7b/0x110\n[ 2030.243388]  worker_thread+0x932/0xe20\n[ 2030.243415]  kthread+0x38a/0x470\n[ 2030.243431]  ? __pfx_worker_thread+0x10/0x10\n[ 2030.243451]  ? __pfx_kthread+0x10/0x10\n[ 2030.243467]  ret_from_fork+0x484/0x910\n[ 2030.243485]  ? __pfx_ret_from_fork+0x10/0x10\n[ 2030.243501]  ? __switch_to+0xc77/0x12c0\n[ 2030.243523]  ? __pfx_kthread+0x10/0x10\n[ 2030.243540]  ret_from_fork_asm+0x1a/0x30\n[ 2030.243564]  </TASK>\n[ 2030.243570]\n[ 2030.290164] Allocated by task 19279:\n[ 2030.290911]  kasan_save_track+0x3e/0x80\n[ 2030.292179]  __kasan_kmalloc+0x72/0x90\n[ 2030.293217]  __kvmalloc_node_noprof+0x3ff/0x6b0\n[ 2030.294467]  handle_generic_event+0x59b/0x750\n[ 2030.295345]  genl_family_rcv_msg_doit+0x238/0x340\n[ 2030.296553]  genl_rcv_msg+0x606/0x7b0\n[ 2030.297129]  netlink_rcv_skb+0x22b/0x4a0\n[ 2030.298500]  genl_rcv+0x2d/0x40\n[ 2030.299273]  netlink_unicast+0x7ba/0x930\n[ 2030.300019]  netlink_sendmsg+0x8c3/0xb00\n[ 2030.301073]  __sock_sendmsg+0xec/0x140\n[ 2030.301579]  __sys_sendto+0x357/0x470\n[ 2030.302255]  __x64_sys_sendto+0xe3/0x100\n[ 2030.303425]  do_syscall_64+0x135/0x460\n[ 2030.304763]  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 2030.305594]\n[ 2030.305819] The buggy address belongs to the object at ffff888121bb6640\n[ 2030.305819]  which belongs to the cache kmalloc-192 of size 192\n[ 2030.309595] The buggy address \n---truncated---","Type":"Description","Title":"ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()"}]}}}