Ryusuke Konishi
d2c539c216
nilfs2: fix use-after-free of nilfs_root in dirtying inodes via iput
...
commit f8654743a0e6909dc634cbfad6db6816f10f3399 upstream.
During unmount process of nilfs2, nothing holds nilfs_root structure after
nilfs2 detaches its writer in nilfs_detach_log_writer(). Previously,
nilfs_evict_inode() could cause use-after-free read for nilfs_root if
inodes are left in "garbage_list" and released by nilfs_dispose_list at
the end of nilfs_detach_log_writer(), and this bug was fixed by commit
9b5a04ac3ad9 ("nilfs2: fix use-after-free bug of nilfs_root in
nilfs_evict_inode()").
However, it turned out that there is another possibility of UAF in the
call path where mark_inode_dirty_sync() is called from iput():
nilfs_detach_log_writer()
nilfs_dispose_list()
iput()
mark_inode_dirty_sync()
__mark_inode_dirty()
nilfs_dirty_inode()
__nilfs_mark_inode_dirty()
nilfs_load_inode_block() --> causes UAF of nilfs_root struct
This can happen after commit 0ae45f63d4 ("vfs: add support for a
lazytime mount option"), which changed iput() to call
mark_inode_dirty_sync() on its final reference if i_state has I_DIRTY_TIME
flag and i_nlink is non-zero.
This issue appears after commit 28a65b49eb53 ("nilfs2: do not write dirty
data after degenerating to read-only") when using the syzbot reproducer,
but the issue has potentially existed before.
Fix this issue by adding a "purging flag" to the nilfs structure, setting
that flag while disposing the "garbage_list" and checking it in
__nilfs_mark_inode_dirty().
Unlike commit 9b5a04ac3ad9 ("nilfs2: fix use-after-free bug of nilfs_root
in nilfs_evict_inode()"), this patch does not rely on ns_writer to
determine whether to skip operations, so as not to break recovery on
mount. The nilfs_salvage_orphan_logs routine dirties the buffer of
salvaged data before attaching the log writer, so changing
__nilfs_mark_inode_dirty() to skip the operation when ns_writer is NULL
will cause recovery write to fail. The purpose of using the cleanup-only
flag is to allow for narrowing of such conditions.
Link: https://lkml.kernel.org/r/20230728191318.33047-1-konishi.ryusuke@gmail.com
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Reported-by: syzbot+74db8b3087f293d3a13a@syzkaller.appspotmail.com
Closes: https://lkml.kernel.org/r/000000000000b4e906060113fd63@google.com
Fixes: 0ae45f63d4 ("vfs: add support for a lazytime mount option")
Tested-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Cc: <stable@vger.kernel.org> # 4.0+
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-08-16 18:19:23 +02:00
..
9p
9p: missing chunk of "fs/9p: Don't update file type when updating file attributes"
2022-06-22 14:11:02 +02:00
adfs
affs
affs: initialize fsdata in affs_truncate()
2023-02-06 07:52:36 +01:00
afs
afs: Fix vlserver probe RTT handling
2023-06-21 15:44:12 +02:00
autofs
befs
bfs
btrfs
btrfs: fix race between quota disable and quota assign ioctls
2023-08-11 11:53:54 +02:00
cachefiles
ceph
ceph: defer stopping mdsc delayed_work
2023-08-11 11:54:01 +02:00
cifs
cifs: Fix potential deadlock when updating vol in cifs_reconnect()
2023-06-28 10:18:37 +02:00
coda
coda: Avoid partial allocation of sig_inputArgs
2023-03-11 16:43:56 +01:00
configfs
configfs: fix possible memory leak in configfs_create_dir()
2023-01-18 11:41:09 +01:00
cramfs
crypto
debugfs
debugfs: regset32: Add Runtime PM support
2023-05-17 11:35:32 +02:00
devpts
fsnotify: fix fsnotify hooks in pseudo filesystems
2022-02-01 17:24:34 +01:00
dlm
fs: dlm: interrupt posix locks only when process is killed
2023-08-11 11:53:45 +02:00
ecryptfs
efivarfs
efs
erofs
erofs: fix compact 4B support for 16k block size
2023-07-27 08:37:35 +02:00
exportfs
ext2
ext2: Drop fragment support
2023-08-11 11:53:59 +02:00
ext4
ext4: fix to check return value of freeze_bdev() in ext4_shutdown()
2023-08-11 11:53:47 +02:00
f2fs
Revert "f2fs: fix potential corruption when moving a directory"
2023-07-27 08:37:26 +02:00
fat
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
freevxfs
fscache
fuse
fuse: revalidate: don't invalidate if interrupted
2023-07-27 08:37:40 +02:00
gfs2
gfs2: Don't deref jdesc in evict
2023-07-27 08:37:03 +02:00
hfs
hfs: fix missing hfs_bnode_get() in __hfs_bnode_create
2023-03-11 16:43:59 +01:00
hfsplus
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
hostfs
hpfs
hugetlbfs
hugetlbfs: fix null-ptr-deref in hugetlbfs_parse_param()
2023-01-18 11:41:38 +01:00
iomap
iomap: iomap_write_failed fix
2022-06-14 18:11:36 +02:00
isofs
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
jbd2
jbd2: Fix wrongly judgement for buffer head removing while doing checkpoint
2023-08-11 11:53:43 +02:00
jffs2
jffs2: reduce stack usage in jffs2_build_xattr_subsystem()
2023-07-27 08:37:25 +02:00
jfs
jfs: jfs_dmap: Validate db_l2nbperpage while mounting
2023-07-27 08:37:35 +02:00
kernfs
kernfs: fix use-after-free in __kernfs_remove
2022-11-03 23:56:54 +09:00
lockd
minix
minix: fix bug when opening a file with O_DIRECT
2022-04-15 14:18:35 +02:00
nfs
NFSv4.1: freeze the session table upon receiving NFS4ERR_BADSESSION
2023-07-27 08:37:18 +02:00
nfs_common
nfsd
NFSD: add encoding of op_recall flag for write delegation
2023-07-27 08:37:24 +02:00
nilfs2
nilfs2: fix use-after-free of nilfs_root in dirtying inodes via iput
2023-08-16 18:19:23 +02:00
nls
notify
fanotify: disallow mount/sb marks on kernel internal pseudo fs
2023-07-27 08:37:26 +02:00
ntfs
ntfs: check overflow when iterating ATTR_RECORDs
2022-11-25 17:42:22 +01:00
ocfs2
ocfs2: check new file size on fallocate call
2023-06-21 15:44:10 +02:00
omfs
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
openpromfs
orangefs
orangefs: Fix kmemleak in orangefs_{kernel,client}_debug_init()
2023-01-18 11:41:39 +01:00
overlayfs
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
proc
mm: hugetlb: proc: check for hugetlb shared PMD in /proc/PID/smaps
2023-02-22 12:50:28 +01:00
pstore
pstore/ram: Add check for kstrdup
2023-07-27 08:37:06 +02:00
qnx4
qnx6
quota
ext4: fix bug_on in __es_tree_search caused by bad quota inode
2023-01-18 11:42:02 +01:00
ramfs
reiserfs
reiserfs: Add security prefix to xattr name in reiserfs_security_write()
2023-05-17 11:35:33 +02:00
romfs
squashfs
revert "squashfs: harden sanity check in squashfs_read_xattr_id_table"
2023-02-22 12:50:39 +01:00
sysfs
sysv
fs/sysv: Null check to prevent null-ptr-deref bug
2023-08-11 11:53:59 +02:00
tracefs
tracefs: Only clobber mode/uid/gid on remount if asked
2022-09-20 12:28:00 +02:00
ubifs
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
udf
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
ufs
unicode
verity
fsverity: don't drop pagecache at end of FS_IOC_ENABLE_VERITY
2023-04-05 11:16:42 +02:00
xfs
xfs: verify buffer contents when we skip log replay
2023-06-28 10:18:42 +02:00
aio.c
aio: fix mremap after fork null-deref
2023-02-22 12:50:35 +01:00
anon_inodes.c
attr.c
vfs: Check the truncate maximum size in inode_newsize_ok()
2022-08-25 11:17:21 +02:00
bad_inode.c
binfmt_aout.c
binfmt: Move install_exec_creds after setup_new_exec to match binfmt_elf
2023-01-18 11:41:46 +01:00
binfmt_elf.c
binfmt_elf_fdpic.c
binfmt: Fix error return code in load_elf_fdpic_binary()
2023-01-18 11:41:46 +01:00
binfmt_em86.c
binfmt_flat.c
binfmt: Move install_exec_creds after setup_new_exec to match binfmt_elf
2023-01-18 11:41:46 +01:00
binfmt_misc.c
binfmt_misc: fix shift-out-of-bounds in check_special_flags
2023-01-18 11:41:33 +01:00
binfmt_script.c
block_dev.c
buffer.c
mm: fs: initialize fsdata passed to write_begin/write_end interface
2022-11-25 17:42:22 +01:00
char_dev.c
chardev: fix error handling in cdev_device_add()
2023-01-18 11:41:25 +01:00
compat.c
compat_binfmt_elf.c
compat_ioctl.c
compat_ioctl: remove /dev/random commands
2022-06-22 14:11:03 +02:00
coredump.c
d_path.c
dax.c
dax: fix cache flush on PMD-mapped pages
2022-06-14 18:11:41 +02:00
dcache.c
dcookies.c
direct-io.c
drop_caches.c
eventfd.c
eventpoll.c
epoll: ep_autoremove_wake_function should use list_del_init_careful
2023-06-28 10:18:35 +02:00
exec.c
exec: Force single empty string when argv is empty
2022-06-06 08:33:50 +02:00
fcntl.c
fhandle.c
file.c
fs: prevent out-of-bounds array speculation when closing a file descriptor
2023-03-17 08:32:47 +01:00
file_table.c
SUNRPC: Ensure we flush any closed sockets before xs_xprt_free()
2022-05-25 09:14:34 +02:00
filesystems.c
fs-writeback.c
writeback: fix call of incorrect macro
2023-05-17 11:35:58 +02:00
fs_context.c
fs: avoid empty option when generating legacy mount string
2023-07-27 08:37:25 +02:00
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c
fs: Establish locking order for unrelated directories
2023-07-27 08:37:26 +02:00
internal.h
fs: Establish locking order for unrelated directories
2023-07-27 08:37:26 +02:00
io_uring.c
io_uring: have io_kill_timeout() honor the request references
2023-06-05 08:17:32 +02:00
ioctl.c
Kconfig
Kconfig.binfmt
libfs.c
libfs: add DEFINE_SIMPLE_ATTRIBUTE_SIGNED for signed value
2023-01-18 11:40:55 +01:00
locks.c
Makefile
mbcache.c
mbcache: Avoid nesting of cache->c_list_lock under bit locks
2023-01-18 11:41:59 +01:00
mount.h
mpage.c
namei.c
fs: no need to check source
2023-07-27 08:37:26 +02:00
namespace.c
no-block.c
nsfs.c
open.c
pipe.c
pnode.c
pnode: terminate at peers of source
2023-01-18 11:41:44 +01:00
pnode.h
posix_acl.c
proc_namespace.c
read_write.c
readdir.c
select.c
seq_file.c
signalfd.c
io_uring: disable polling pollfree files
2022-09-05 10:27:47 +02:00
splice.c
Revert "fs: check FMODE_LSEEK to control internal pipe splicing"
2022-10-17 17:24:32 +02:00
stack.c
stat.c
stat: fix inconsistency between struct stat and struct compat_stat
2022-04-27 13:50:48 +02:00
statfs.c
statfs: enforce statfs[64] structure initialization
2023-05-30 12:44:07 +01:00
super.c
fs: Protect reconfiguration of sb read-write from racing writes
2023-08-11 11:53:59 +02:00
sync.c
timerfd.c
userfaultfd.c
userfaultfd: open userfaultfds with O_RDONLY
2022-10-26 13:22:21 +02:00
utimes.c
xattr.c
fs: don't audit the capability check in simple_xattr_list()
2023-01-18 11:40:53 +01:00