yangerkun
5233f4465e
block: reexpand iov_iter after read/write
[ Upstream commit cf7b39a0cbf6bf57aa07a008d46cf695add05b4c ]
We get a bug:
BUG: KASAN: slab-out-of-bounds in iov_iter_revert+0x11c/0x404
lib/iov_iter.c:1139
Read of size 8 at addr ffff0000d3fb11f8 by task
CPU: 0 PID: 12582 Comm: syz-executor.2 Not tainted
5.10.0-00843-g352c8610ccd2 #2
Hardware name: linux,dummy-virt (DT)
Call trace:
dump_backtrace+0x0/0x2d0 arch/arm64/kernel/stacktrace.c:132
show_stack+0x28/0x34 arch/arm64/kernel/stacktrace.c:196
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x110/0x164 lib/dump_stack.c:118
print_address_description+0x78/0x5c8 mm/kasan/report.c:385
__kasan_report mm/kasan/report.c:545 [inline]
kasan_report+0x148/0x1e4 mm/kasan/report.c:562
check_memory_region_inline mm/kasan/generic.c:183 [inline]
__asan_load8+0xb4/0xbc mm/kasan/generic.c:252
iov_iter_revert+0x11c/0x404 lib/iov_iter.c:1139
io_read fs/io_uring.c:3421 [inline]
io_issue_sqe+0x2344/0x2d64 fs/io_uring.c:5943
__io_queue_sqe+0x19c/0x520 fs/io_uring.c:6260
io_queue_sqe+0x2a4/0x590 fs/io_uring.c:6326
io_submit_sqe fs/io_uring.c:6395 [inline]
io_submit_sqes+0x4c0/0xa04 fs/io_uring.c:6624
__do_sys_io_uring_enter fs/io_uring.c:9013 [inline]
__se_sys_io_uring_enter fs/io_uring.c:8960 [inline]
__arm64_sys_io_uring_enter+0x190/0x708 fs/io_uring.c:8960
__invoke_syscall arch/arm64/kernel/syscall.c:36 [inline]
invoke_syscall arch/arm64/kernel/syscall.c:48 [inline]
el0_svc_common arch/arm64/kernel/syscall.c:158 [inline]
do_el0_svc+0x120/0x290 arch/arm64/kernel/syscall.c:227
el0_svc+0x1c/0x28 arch/arm64/kernel/entry-common.c:367
el0_sync_handler+0x98/0x170 arch/arm64/kernel/entry-common.c:383
el0_sync+0x140/0x180 arch/arm64/kernel/entry.S:670
Allocated by task 12570:
stack_trace_save+0x80/0xb8 kernel/stacktrace.c:121
kasan_save_stack mm/kasan/common.c:48 [inline]
kasan_set_track mm/kasan/common.c:56 [inline]
__kasan_kmalloc+0xdc/0x120 mm/kasan/common.c:461
kasan_kmalloc+0xc/0x14 mm/kasan/common.c:475
__kmalloc+0x23c/0x334 mm/slub.c:3970
kmalloc include/linux/slab.h:557 [inline]
__io_alloc_async_data+0x68/0x9c fs/io_uring.c:3210
io_setup_async_rw fs/io_uring.c:3229 [inline]
io_read fs/io_uring.c:3436 [inline]
io_issue_sqe+0x2954/0x2d64 fs/io_uring.c:5943
__io_queue_sqe+0x19c/0x520 fs/io_uring.c:6260
io_queue_sqe+0x2a4/0x590 fs/io_uring.c:6326
io_submit_sqe fs/io_uring.c:6395 [inline]
io_submit_sqes+0x4c0/0xa04 fs/io_uring.c:6624
__do_sys_io_uring_enter fs/io_uring.c:9013 [inline]
__se_sys_io_uring_enter fs/io_uring.c:8960 [inline]
__arm64_sys_io_uring_enter+0x190/0x708 fs/io_uring.c:8960
__invoke_syscall arch/arm64/kernel/syscall.c:36 [inline]
invoke_syscall arch/arm64/kernel/syscall.c:48 [inline]
el0_svc_common arch/arm64/kernel/syscall.c:158 [inline]
do_el0_svc+0x120/0x290 arch/arm64/kernel/syscall.c:227
el0_svc+0x1c/0x28 arch/arm64/kernel/entry-common.c:367
el0_sync_handler+0x98/0x170 arch/arm64/kernel/entry-common.c:383
el0_sync+0x140/0x180 arch/arm64/kernel/entry.S:670
Freed by task 12570:
stack_trace_save+0x80/0xb8 kernel/stacktrace.c:121
kasan_save_stack mm/kasan/common.c:48 [inline]
kasan_set_track+0x38/0x6c mm/kasan/common.c:56
kasan_set_free_info+0x20/0x40 mm/kasan/generic.c:355
__kasan_slab_free+0x124/0x150 mm/kasan/common.c:422
kasan_slab_free+0x10/0x1c mm/kasan/common.c:431
slab_free_hook mm/slub.c:1544 [inline]
slab_free_freelist_hook mm/slub.c:1577 [inline]
slab_free mm/slub.c:3142 [inline]
kfree+0x104/0x38c mm/slub.c:4124
io_dismantle_req fs/io_uring.c:1855 [inline]
__io_free_req+0x70/0x254 fs/io_uring.c:1867
io_put_req_find_next fs/io_uring.c:2173 [inline]
__io_queue_sqe+0x1fc/0x520 fs/io_uring.c:6279
__io_req_task_submit+0x154/0x21c fs/io_uring.c:2051
io_req_task_submit+0x2c/0x44 fs/io_uring.c:2063
task_work_run+0xdc/0x128 kernel/task_work.c:151
get_signal+0x6f8/0x980 kernel/signal.c:2562
do_signal+0x108/0x3a4 arch/arm64/kernel/signal.c:658
do_notify_resume+0xbc/0x25c arch/arm64/kernel/signal.c:722
work_pending+0xc/0x180
blkdev_read_iter can truncate iov_iter's count since the count + pos may
exceed the size of the blkdev. This will confuse io_read that we have
consume the iovec. And once we do the iov_iter_revert in io_read, we
will trigger the slab-out-of-bounds. Fix it by reexpand the count with
size has been truncated.
blkdev_write_iter can trigger the problem too.
Signed-off-by: yangerkun <yangerkun@huawei.com>
Acked-by: Pavel Begunkov <asml.silencec@gmail.com>
Link: https://lore.kernel.org/r/20210401071807.3328235-1-yangerkun@huawei.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2021-05-22 11:38:29 +02:00 |
| .. |
|
9p
|
9P: Cast to loff_t before multiplying
|
2020-11-05 11:43:34 +01:00 |
|
adfs
|
|
|
|
affs
|
fs/affs: release old buffer head on error path
|
2021-03-04 10:26:48 +01:00 |
|
afs
|
afs: Stop listxattr() from listing "afs.*" attributes
|
2021-03-24 11:26:37 +01:00 |
|
autofs
|
|
|
|
befs
|
|
|
|
bfs
|
bfs: don't use WARNING: string when it's just info.
|
2021-01-06 14:48:39 +01:00 |
|
btrfs
|
btrfs: fix race when picking most recent mod log operation for an old root
|
2021-05-11 14:04:14 +02:00 |
|
cachefiles
|
cachefiles: Handle readpage error correctly
|
2020-11-05 11:43:36 +01:00 |
|
ceph
|
ceph: fix fscache invalidation
|
2021-05-22 11:38:29 +02:00 |
|
cifs
|
cifs: Return correct error code from smb2_get_enc_key
|
2021-05-11 14:04:04 +02:00 |
|
coda
|
|
|
|
configfs
|
configfs: fix a use-after-free in __configfs_open_file
|
2021-03-17 17:03:56 +01:00 |
|
cramfs
|
|
|
|
crypto
|
fscrypt: remove kernel-internal constants from UAPI header
|
2021-01-06 14:48:35 +01:00 |
|
debugfs
|
debugfs: do not attempt to create a new file before the filesystem is initalized
|
2021-03-04 10:26:10 +01:00 |
|
devpts
|
|
|
|
dlm
|
fs: dlm: fix debugfs dump
|
2021-05-19 10:08:20 +02:00 |
|
ecryptfs
|
ecryptfs: fix kernel panic with null dev_name
|
2021-05-11 14:04:02 +02:00 |
|
efivarfs
|
efivarfs: revert "fix memory leak in efivarfs_create()"
|
2020-12-02 08:49:53 +01:00 |
|
efs
|
|
|
|
erofs
|
erofs: add unsupported inode i_format check
|
2021-05-11 14:04:02 +02:00 |
|
exportfs
|
|
|
|
ext2
|
ext2: don't update mtime on COW faults
|
2020-09-09 19:12:30 +02:00 |
|
ext4
|
ext4: fix error code in ext4_commit_super
|
2021-05-11 14:04:16 +02:00 |
|
f2fs
|
f2fs: fix error handling in f2fs_end_enable_verity()
|
2021-05-19 10:08:32 +02:00 |
|
fat
|
fat: don't allow to mount if the FAT length == 0
|
2020-06-17 16:40:36 +02:00 |
|
freevxfs
|
|
|
|
fscache
|
|
|
|
fuse
|
cuse: prevent clone
|
2021-05-19 10:08:22 +02:00 |
|
gfs2
|
gfs2: report "already frozen/thawed" errors
|
2021-04-16 11:46:37 +02:00 |
|
hfs
|
|
|
|
hfsplus
|
hfsplus: prevent corruption in shrinking truncate
|
2021-05-19 10:08:29 +02:00 |
|
hostfs
|
hostfs: fix memory handling in follow_link()
|
2021-04-14 08:24:14 +02:00 |
|
hpfs
|
|
|
|
hugetlbfs
|
mm/hugetlb: fix F_SEAL_FUTURE_WRITE
|
2021-05-19 10:08:29 +02:00 |
|
iomap
|
iomap: fix sub-page uptodate handling
|
2021-05-19 10:08:30 +02:00 |
|
isofs
|
isofs: release buffer head before return
|
2021-03-04 10:26:30 +01:00 |
|
jbd2
|
jbd2: fix up sparse warnings in checkpoint code
|
2020-11-18 19:20:30 +01:00 |
|
jffs2
|
jffs2: check the validity of dstlen in jffs2_zlib_compress()
|
2021-05-11 14:04:16 +02:00 |
|
jfs
|
JFS: more checks for invalid superblock
|
2021-03-07 12:20:41 +01:00 |
|
kernfs
|
kernfs: do not call fsnotify() with name without a parent
|
2020-08-19 08:16:12 +02:00 |
|
lockd
|
lockd: don't use interval-based rebinding over TCP
|
2020-12-30 11:51:16 +01:00 |
|
minix
|
fs/minix: remove expected error message in block_to_path()
|
2020-08-21 13:05:37 +02:00 |
|
nfs
|
NFSv4.2 fix handling of sr_eof in SEEK's reply
|
2021-05-19 10:08:25 +02:00 |
|
nfs_common
|
nfs_common: need lock during iterate through the list
|
2020-12-30 11:51:22 +01:00 |
|
nfsd
|
NFSD: fix error handling in NFSv4.0 callbacks
|
2021-04-07 14:47:39 +02:00 |
|
nilfs2
|
nilfs2: fix null pointer dereference at nilfs_segctor_do_construct()
|
2020-06-17 16:40:29 +02:00 |
|
nls
|
|
|
|
notify
|
fanotify: fix ignore mask logic for events on child and on dir
|
2020-06-17 16:40:24 +02:00 |
|
ntfs
|
ntfs: check for valid standard information attribute
|
2021-02-26 10:10:27 +01:00 |
|
ocfs2
|
ocfs2: fix deadlock between setattr and dio_end_io_write
|
2021-04-14 08:24:10 +02:00 |
|
omfs
|
|
|
|
openpromfs
|
|
|
|
orangefs
|
orangefs: get rid of knob code...
|
2020-08-21 13:05:29 +02:00 |
|
overlayfs
|
ovl: fix missing revert_creds() on error path
|
2021-05-14 09:44:16 +02:00 |
|
proc
|
proc: fix lookup in /proc/net subdirectories after setns(2)
|
2021-01-12 20:16:10 +01:00 |
|
pstore
|
pstore: Fix typo in compression option name
|
2021-03-04 10:26:45 +01:00 |
|
qnx4
|
|
|
|
qnx6
|
|
|
|
quota
|
quota: Fix memory leak when handling corrupted quota file
|
2021-03-04 10:26:26 +01:00 |
|
ramfs
|
ramfs: fix nommu mmap with gaps in the page cache
|
2020-10-29 09:57:53 +01:00 |
|
reiserfs
|
reiserfs: update reiserfs_xattrs_initialized() condition
|
2021-04-07 14:47:43 +02:00 |
|
romfs
|
romfs: fix uninitialized memory leak in romfs_dev_read()
|
2020-08-26 10:40:51 +02:00 |
|
squashfs
|
squashfs: fix divide error in calculate_skip()
|
2021-05-19 10:08:29 +02:00 |
|
sysfs
|
sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output
|
2021-03-07 12:20:48 +01:00 |
|
sysv
|
|
|
|
tracefs
|
|
|
|
ubifs
|
ubifs: Only check replay with inode type to judge if inode linked
|
2021-05-11 14:04:14 +02:00 |
|
udf
|
udf: fix silent AED tagLocation corruption
|
2021-03-17 17:03:41 +01:00 |
|
ufs
|
fs/ufs: avoid potential u32 multiplication overflow
|
2020-08-21 13:05:37 +02:00 |
|
unicode
|
|
|
|
verity
|
|
|
|
xfs
|
xfs: Fix assert failure in xfs_setattr_size()
|
2021-03-07 12:20:42 +01:00 |
|
aio.c
|
aio: fix async fsync creds
|
2020-06-17 16:40:24 +02:00 |
|
anon_inodes.c
|
|
|
|
attr.c
|
|
|
|
bad_inode.c
|
|
|
|
binfmt_aout.c
|
|
|
|
binfmt_elf.c
|
fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info()
|
2020-06-03 08:21:27 +02:00 |
|
binfmt_elf_fdpic.c
|
|
|
|
binfmt_em86.c
|
|
|
|
binfmt_flat.c
|
binfmt_flat: revert "binfmt_flat: don't offset the data start"
|
2020-09-03 11:26:39 +02:00 |
|
binfmt_misc.c
|
binfmt_misc: fix possible deadlock in bm_register_write
|
2021-03-17 17:03:57 +01:00 |
|
binfmt_script.c
|
|
|
|
block_dev.c
|
block: reexpand iov_iter after read/write
|
2021-05-22 11:38:29 +02:00 |
|
buffer.c
|
fs: Don't invalidate page buffers in block_write_full_page()
|
2020-11-05 11:43:24 +01:00 |
|
char_dev.c
|
|
|
|
compat.c
|
|
|
|
compat_binfmt_elf.c
|
|
|
|
compat_ioctl.c
|
|
|
|
coredump.c
|
coredump: fix core_pattern parse error
|
2020-12-11 13:23:30 +01:00 |
|
d_path.c
|
fs: fix NULL dereference due to data race in prepend_path()
|
2020-10-29 09:57:45 +01:00 |
|
dax.c
|
mm: provide a saner PTE walking API for modules
|
2021-02-26 10:10:28 +01:00 |
|
dcache.c
|
fix dget_parent() fastpath race
|
2020-10-01 13:17:19 +02:00 |
|
dcookies.c
|
|
|
|
direct-io.c
|
fs: direct-io: fix missing sdio->boundary
|
2021-04-14 08:24:11 +02:00 |
|
drop_caches.c
|
|
|
|
eventfd.c
|
|
|
|
eventpoll.c
|
ep_create_wakeup_source(): dentry name can change under you...
|
2020-10-07 08:01:31 +02:00 |
|
exec.c
|
exec: Transform exec_update_mutex into a rw_semaphore
|
2021-01-09 13:44:55 +01:00 |
|
fcntl.c
|
fcntl: Fix potential deadlock in send_sig{io, urg}()
|
2021-01-06 14:48:39 +01:00 |
|
fhandle.c
|
|
|
|
file.c
|
fix multiplication overflow in copy_fdtable()
|
2020-05-27 17:46:12 +02:00 |
|
file_table.c
|
|
|
|
filesystems.c
|
fs/filesystems.c: downgrade user-reachable WARN_ONCE() to pr_warn_once()
|
2020-04-17 10:50:21 +02:00 |
|
fs-writeback.c
|
fs: fix lazytime expiration handling in __writeback_single_inode()
|
2021-01-30 13:54:11 +01:00 |
|
fs_context.c
|
|
|
|
fs_parser.c
|
|
|
|
fs_pin.c
|
|
|
|
fs_struct.c
|
|
|
|
fs_types.c
|
|
|
|
fsopen.c
|
|
|
|
inode.c
|
futex: Fix inode life-time issue
|
2020-03-25 08:25:58 +01:00 |
|
internal.h
|
|
|
|
io_uring.c
|
io_uring: Fix current->fs handling in io_sq_wq_submit_work()
|
2021-01-30 13:54:10 +01:00 |
|
ioctl.c
|
|
|
|
Kconfig
|
|
|
|
Kconfig.binfmt
|
|
|
|
libfs.c
|
libfs: fix error cast of negative value in simple_attr_write()
|
2020-11-24 13:29:19 +01:00 |
|
locks.c
|
locks: reinstate locks_delete_block optimization
|
2020-03-25 08:25:41 +01:00 |
|
Makefile
|
|
|
|
mbcache.c
|
|
|
|
mount.h
|
|
|
|
mpage.c
|
|
|
|
namei.c
|
|
|
|
namespace.c
|
fs/namespace.c: WARN if mnt_count has become negative
|
2021-01-06 14:48:40 +01:00 |
|
no-block.c
|
|
|
|
nsfs.c
|
|
|
|
open.c
|
cifs_atomic_open(): fix double-put on late allocation failure
|
2020-03-18 07:17:51 +01:00 |
|
pipe.c
|
|
|
|
pnode.c
|
propagate_one(): mnt_set_mountpoint() needs mount_lock
|
2020-05-02 08:48:44 +02:00 |
|
pnode.h
|
mount: fix mounting of detached mounts onto targets that reside on shared mounts
|
2021-03-17 17:03:33 +01:00 |
|
posix_acl.c
|
|
|
|
proc_namespace.c
|
|
|
|
read_write.c
|
|
|
|
readdir.c
|
readdir: make sure to verify directory entry for legacy interfaces too
|
2021-04-21 12:56:16 +02:00 |
|
select.c
|
kernel, fs: Introduce and use set_restart_fn() and arch_set_restart_data()
|
2021-03-24 11:26:44 +01:00 |
|
seq_file.c
|
|
|
|
signalfd.c
|
fs/signalfd.c: fix inconsistent return codes for signalfd4
|
2020-08-26 10:40:58 +02:00 |
|
splice.c
|
|
|
|
stack.c
|
|
|
|
stat.c
|
|
|
|
statfs.c
|
|
|
|
super.c
|
vfs: remove lockdep bogosity in __sb_start_write
|
2020-11-24 13:29:01 +01:00 |
|
sync.c
|
|
|
|
timerfd.c
|
|
|
|
userfaultfd.c
|
|
|
|
utimes.c
|
|
|
|
xattr.c
|
xattr: break delegations in {set,remove}xattr
|
2020-08-11 15:33:39 +02:00 |