This is a note to let you know that I've just added the patch titled cifs: fix CIFS_IOC_GET_MNT_INFO oops to the 4.11-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: cifs-fix-cifs_ioc_get_mnt_info-oops.patch and it can be found in the queue-4.11 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From d8a6e505d6bba2250852fbc1c1c86fe68aaf9af3 Mon Sep 17 00:00:00 2001 From: David Disseldorp <ddiss@xxxxxxx> Date: Thu, 4 May 2017 00:41:13 +0200 Subject: cifs: fix CIFS_IOC_GET_MNT_INFO oops From: David Disseldorp <ddiss@xxxxxxx> commit d8a6e505d6bba2250852fbc1c1c86fe68aaf9af3 upstream. An open directory may have a NULL private_data pointer prior to readdir. Fixes: 0de1f4c6f6c0 ("Add way to query server fs info for smb3") Signed-off-by: David Disseldorp <ddiss@xxxxxxx> Signed-off-by: Steve French <smfrench@xxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- fs/cifs/ioctl.c | 2 ++ 1 file changed, 2 insertions(+) --- a/fs/cifs/ioctl.c +++ b/fs/cifs/ioctl.c @@ -209,6 +209,8 @@ long cifs_ioctl(struct file *filep, unsi rc = -EOPNOTSUPP; break; case CIFS_IOC_GET_MNT_INFO: + if (pSMBFile == NULL) + break; tcon = tlink_tcon(pSMBFile->tlink); rc = smb_mnt_get_fsinfo(xid, tcon, (void __user *)arg); break; Patches currently in stable-queue which might be from ddiss@xxxxxxx are queue-4.11/cifs-fix-cifs_ioc_get_mnt_info-oops.patch queue-4.11/target-fileio-fix-zero-length-read-and-write-handling.patch queue-4.11/cifs-fix-cifs_enumerate_snapshots-oops.patch queue-4.11/cifs-fix-leak-in-fsctl_enum_snaps-response-handling.patch