From 2f9af06e30b78ccb6f2708d89793180c29e4feef Mon Sep 17 00:00:00 2001 From: Thomas Huth Date: Wed, 12 Aug 2026 15:01:51 +0200 Subject: [PATCH] smb: client: Clear sensitive stack data in smb1encrypt.c Make sure to not leak signature data via the stack, clear it with memzero_explicit() before leaving the function. To avoid that we have to introduce "goto"-cleanup here, we re-arrange the code a little bit (and drop the commented cifs_dump_mem debug code that looks like a leftover from very early days). Signed-off-by: Thomas Huth Signed-off-by: Namjae Jeon Signed-off-by: Paulo Alcantara --- fs/smb/client/smb1encrypt.c | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/fs/smb/client/smb1encrypt.c b/fs/smb/client/smb1encrypt.c index bf10fdeeedca..c9eb68f04e7b 100644 --- a/fs/smb/client/smb1encrypt.c +++ b/fs/smb/client/smb1encrypt.c @@ -81,6 +81,7 @@ int cifs_sign_rqst(struct smb_rqst *rqst, struct TCP_Server_Info *server, else memcpy(cifs_pdu->Signature.SecuritySignature, smb_signature, 8); + memzero_explicit(smb_signature, sizeof(smb_signature)); return rc; } @@ -126,15 +127,13 @@ int cifs_verify_signature(struct smb_rqst *rqst, rc = cifs_calc_signature(rqst, server, what_we_think_sig_should_be); cifs_server_unlock(server); - if (rc) - return rc; - -/* cifs_dump_mem("what we think it should be: ", - what_we_think_sig_should_be, 16); */ - - if (crypto_memneq(server_response_sig, what_we_think_sig_should_be, 8)) - return -EACCES; - else - return 0; + if (!rc) { + if (crypto_memneq(server_response_sig, + what_we_think_sig_should_be, 8)) + rc = -EACCES; + } + memzero_explicit(what_we_think_sig_should_be, + sizeof(what_we_think_sig_should_be)); + return rc; }