7.2.8 и сделала patch:
From 8a3f2c1d4e5b6f7a8b9c0d1e2f3a4b5c6d7e8f9a Mon Sep 17 00:00:00 2001
From: onlylun <hidden@yandex.ru>
Date: Sun, 28 Sep 2026 02:45:00 +0500
Subject: [PATCH] ksmbd: fix -ENOENT on FSCTL_PIPE_TRANSCEIVE for IPC pipes
IPC pipe create (create_smb2_pipe) stores the RPC handle from
ksmbd_ipc_id_alloc() as VolatileFileId, without creating a
ksmbd_file entry in the file table.
The recent hardening series (CVE-2026-52944 and related fixes)
introduced a common ksmbd_lookup_fd_slow() call in smb2_ioctl()
before the FSCTL switch, guarded by a no_fileid_ioctl whitelist.
However, FSCTL_PIPE_TRANSCEIVE was not added to that list.
As a result, when a client sends FSCTL_PIPE_TRANSCEIVE on an IPC
pipe, smb2_ioctl() attempts a file table lookup using the RPC
handle as the file ID, fails to find it, and returns -ENOENT.
This breaks all named pipe transceive operations (srvsvc, lsarpc,
samr, wkssvc, LANMAN).
Add FSCTL_PIPE_TRANSCEIVE to the no_fileid_ioctl list so that
smb2_ioctl() skips the file lookup and passes the handle directly
to fsctl_pipe_transceive(), as intended.
Fixes: ("ksmbd: add file lookup validation in smb2_ioctl")
Cc: hidden@vger.kernel.org
Signed-off-by: onlylun <hidden@yandex.ru>
---
fs/smb/server/smb2pdu.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index abcdef1..1234567 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -9620,6 +9620,7 @@ int smb2_ioctl(struct ksmbd_work *work)
case FSCTL_DFS_GET_REFERRALS_EX:
case FSCTL_QUERY_NETWORK_INTERFACE_INFO:
case FSCTL_VALIDATE_NEGOTIATE_INFO:
case FSCTL_PIPE_WAIT:
+ case FSCTL_PIPE_TRANSCEIVE:
no_fileid_ioctl = true;
break;
default:
--
2.45.0
AI писателям ядра все-таки нужен считаю, а то стареют видимо.











