Mikulas Patocka
384ef33d37
md: fix a crash in mempool_free
commit 341097ee53573e06ab9fc675d96a052385b851fa upstream.
There's a crash in mempool_free when running the lvm test
shell/lvchange-rebuild-raid.sh.
The reason for the crash is this:
* super_written calls atomic_dec_and_test(&mddev->pending_writes) and
wake_up(&mddev->sb_wait). Then it calls rdev_dec_pending(rdev, mddev)
and bio_put(bio).
* so, the process that waited on sb_wait and that is woken up is racing
with bio_put(bio).
* if the process wins the race, it calls bioset_exit before bio_put(bio)
is executed.
* bio_put(bio) attempts to free a bio into a destroyed bio set - causing
a crash in mempool_free.
We fix this bug by moving bio_put before atomic_dec_and_test.
We also move rdev_dec_pending before atomic_dec_and_test as suggested by
Neil Brown.
The function md_end_flush has a similar bug - we must call bio_put before
we decrement the number of in-progress bios.
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor write access in kernel mode
#PF: error_code(0x0002) - not-present page
PGD 11557f0067 P4D 11557f0067 PUD 0
Oops: 0002 [#1] PREEMPT SMP
CPU: 0 PID: 73 Comm: kworker/0:1 Not tainted 6.1.0-rc3 #5
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014
Workqueue: kdelayd flush_expired_bios [dm_delay]
RIP: 0010:mempool_free+0x47/0x80
Code: 48 89 ef 5b 5d ff e0 f3 c3 48 89 f7 e8 32 45 3f 00 48 63 53 08 48 89 c6 3b 53 04 7d 2d 48 8b 43 10 8d 4a 01 48 89 df 89 4b 08 <48> 89 2c d0 e8 b0 45 3f 00 48 8d 7b 30 5b 5d 31 c9 ba 01 00 00 00
RSP: 0018:ffff88910036bda8 EFLAGS: 00010093
RAX: 0000000000000000 RBX: ffff8891037b65d8 RCX: 0000000000000001
RDX: 0000000000000000 RSI: 0000000000000202 RDI: ffff8891037b65d8
RBP: ffff8891447ba240 R08: 0000000000012908 R09: 00000000003d0900
R10: 0000000000000000 R11: 0000000000173544 R12: ffff889101a14000
R13: ffff8891562ac300 R14: ffff889102b41440 R15: ffffe8ffffa00d05
FS: 0000000000000000(0000) GS:ffff88942fa00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000001102e99000 CR4: 00000000000006b0
Call Trace:
<TASK>
clone_endio+0xf4/0x1c0 [dm_mod]
clone_endio+0xf4/0x1c0 [dm_mod]
__submit_bio+0x76/0x120
submit_bio_noacct_nocheck+0xb6/0x2a0
flush_expired_bios+0x28/0x2f [dm_delay]
process_one_work+0x1b4/0x300
worker_thread+0x45/0x3e0
? rescuer_thread+0x380/0x380
kthread+0xc2/0x100
? kthread_complete_and_exit+0x20/0x20
ret_from_fork+0x1f/0x30
</TASK>
Modules linked in: brd dm_delay dm_raid dm_mod af_packet uvesafb cfbfillrect cfbimgblt cn cfbcopyarea fb font fbdev tun autofs4 binfmt_misc configfs ipv6 virtio_rng virtio_balloon rng_core virtio_net pcspkr net_failover failover qemu_fw_cfg button mousedev raid10 raid456 libcrc32c async_raid6_recov async_memcpy async_pq raid6_pq async_xor xor async_tx raid1 raid0 md_mod sd_mod t10_pi crc64_rocksoft crc64 virtio_scsi scsi_mod evdev psmouse bsg scsi_common [last unloaded: brd]
CR2: 0000000000000000
---[ end trace 0000000000000000 ]---
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Song Liu <song@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2023-01-18 11:41:44 +01:00 |
| .. |
|
accessibility
|
|
|
|
acpi
|
ACPICA: Fix error code path in acpi_ds_call_control_method()
|
2023-01-18 11:41:34 +01:00 |
|
amba
|
|
|
|
android
|
binder: Gracefully handle BINDER_TYPE_FDA objects with num_fds=0
|
2022-12-08 11:23:01 +01:00 |
|
ata
|
ata: ahci: Fix PCS quirk application for suspend
|
2023-01-18 11:41:42 +01:00 |
|
atm
|
|
|
|
auxdisplay
|
|
|
|
base
|
class: fix possible memory leak in __class_register()
|
2023-01-18 11:41:21 +01:00 |
|
bcma
|
|
|
|
block
|
drbd: use after free in drbd_create_device()
|
2022-11-25 17:42:16 +01:00 |
|
bluetooth
|
Bluetooth: hci_bcsp: don't call kfree_skb() under spin_lock_irqsave()
|
2023-01-18 11:41:16 +01:00 |
|
bus
|
bus: sunxi-rsb: Support atomic transfers
|
2022-12-08 11:22:57 +01:00 |
|
cdrom
|
|
|
|
char
|
ipmi: fix memleak when unload ipmi driver
|
2023-01-18 11:41:35 +01:00 |
|
clk
|
clk: st: Fix memory leak in st_of_quadfs_setup()
|
2023-01-18 11:41:38 +01:00 |
|
clocksource
|
clocksource/drivers/sh_cmt: Make sure channel clock supply is enabled
|
2023-01-18 11:40:56 +01:00 |
|
connector
|
|
|
|
counter
|
counter: stm32-lptimer-cnt: fix the check on arr and cmp registers update
|
2023-01-18 11:41:24 +01:00 |
|
cpufreq
|
cpufreq: amd_freq_sensitivity: Add missing pci_dev_put()
|
2023-01-18 11:40:55 +01:00 |
|
cpuidle
|
cpuidle: dt: Return the correct numbers of parsed idle states
|
2023-01-18 11:40:53 +01:00 |
|
crypto
|
crypto: img-hash - Fix variable dereferenced before check 'hdev->req'
|
2023-01-18 11:41:21 +01:00 |
|
dax
|
|
|
|
dca
|
|
|
|
devfreq
|
|
|
|
dio
|
drivers: dio: fix possible memory leak in dio_init()
|
2023-01-18 11:41:21 +01:00 |
|
dma
|
dmaengine: at_hdmac: Check return code of dma_async_device_register
|
2022-11-25 17:42:10 +01:00 |
|
dma-buf
|
udmabuf: Set the DMA mask for the udmabuf device (v2)
|
2022-09-05 10:27:45 +02:00 |
|
edac
|
EDAC/i10nm: fix refcount leak in pci_get_dev_wrapper()
|
2023-01-18 11:40:55 +01:00 |
|
eisa
|
|
|
|
extcon
|
|
|
|
firewire
|
|
|
|
firmware
|
firmware: coreboot: Register bus in module init
|
2022-12-08 11:23:00 +01:00 |
|
fpga
|
|
|
|
fsi
|
fsi: core: Check error number after calling ida_simple_get
|
2022-10-26 13:22:41 +02:00 |
|
gnss
|
|
|
|
gpio
|
gpio: amd8111: Fix PCI device reference count leak
|
2022-12-14 11:30:44 +01:00 |
|
gpu
|
drm/sti: Fix return type of sti_{dvo,hda,hdmi}_connector_mode_valid()
|
2023-01-18 11:41:39 +01:00 |
|
greybus
|
|
|
|
hid
|
HID: plantronics: Additional PIDs for double volume key presses quirk
|
2023-01-18 11:41:43 +01:00 |
|
hsi
|
HSI: omap_ssi_core: Fix error handling in ssi_init()
|
2023-01-18 11:41:28 +01:00 |
|
hv
|
Drivers: hv: vmbus: fix possible memory leak in vmbus_device_register()
|
2022-12-08 11:22:58 +01:00 |
|
hwmon
|
hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new()
|
2022-12-08 11:23:03 +01:00 |
|
hwspinlock
|
|
|
|
hwtracing
|
|
|
|
i2c
|
i2c: ismt: Fix an out-of-bounds bug in ismt_access()
|
2023-01-18 11:41:26 +01:00 |
|
i3c
|
|
|
|
ide
|
|
|
|
idle
|
intel_idle: Disable IBRS during long idle
|
2022-10-07 09:16:55 +02:00 |
|
iio
|
iio: adc128s052: add proper .data members in adc128_of_match table
|
2023-01-18 11:41:41 +01:00 |
|
infiniband
|
RDMA/siw: Fix pointer cast warning
|
2023-01-18 11:41:29 +01:00 |
|
input
|
Input: elants_i2c - properly handle the reset GPIO when power is off
|
2023-01-18 11:41:03 +01:00 |
|
interconnect
|
|
|
|
iommu
|
iommu/fsl_pamu: Fix resource leak in fsl_pamu_probe()
|
2023-01-18 11:41:29 +01:00 |
|
ipack
|
|
|
|
irqchip
|
irqchip: gic-pm: Use pm_runtime_resume_and_get() in gic_probe()
|
2023-01-18 11:40:54 +01:00 |
|
isdn
|
mISDN: hfcmulti: don't call dev_kfree_skb/kfree_skb() under spin_lock_irqsave()
|
2023-01-18 11:41:32 +01:00 |
|
leds
|
|
|
|
lightnvm
|
|
|
|
macintosh
|
macintosh/macio-adb: check the return value of ioremap()
|
2023-01-18 11:41:29 +01:00 |
|
mailbox
|
mailbox: zynq-ipi: fix error handling while device_register() fails
|
2023-01-18 11:41:33 +01:00 |
|
mcb
|
mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
|
2023-01-18 11:41:25 +01:00 |
|
md
|
md: fix a crash in mempool_free
|
2023-01-18 11:41:44 +01:00 |
|
media
|
media: dvbdev: fix refcnt bug
|
2023-01-18 11:41:42 +01:00 |
|
memory
|
memory: of: Fix refcount leak bug in of_get_ddr_timings()
|
2022-10-26 13:22:31 +02:00 |
|
memstick
|
|
|
|
message
|
|
|
|
mfd
|
mfd: sm501: Add check for platform_driver_register()
|
2022-10-26 13:22:42 +02:00 |
|
misc
|
cxl: Fix refcount leak in cxl_calc_capp_routing
|
2023-01-18 11:41:30 +01:00 |
|
mmc
|
mmc: f-sdh30: Add quirks for broken timeout clock capability
|
2023-01-18 11:41:38 +01:00 |
|
mtd
|
mtd: maps: pxa2xx-flash: fix memory leak in probe
|
2023-01-18 11:41:05 +01:00 |
|
mux
|
|
|
|
net
|
ppp: associate skb with a device at tx
|
2023-01-18 11:41:37 +01:00 |
|
nfc
|
nfc: pn533: Clear nfc_target before being used
|
2023-01-18 11:41:32 +01:00 |
|
ntb
|
|
|
|
nubus
|
|
|
|
nvdimm
|
|
|
|
nvme
|
nvme-pci: fix doorbell buffer value endianness
|
2023-01-18 11:41:42 +01:00 |
|
nvmem
|
|
|
|
of
|
of: overlay: fix null pointer dereferencing in find_dup_cset_node_entry() and find_dup_cset_prop()
|
2023-01-18 11:41:14 +01:00 |
|
opp
|
|
|
|
oprofile
|
|
|
|
parisc
|
parisc: Export iosapic_serial_irq() symbol for serial port driver
|
2022-11-10 17:57:56 +01:00 |
|
parport
|
parport_pc: Avoid FIFO port location truncation
|
2022-11-25 17:42:14 +01:00 |
|
pci
|
PCI: Check for alloc failure in pci_request_irq()
|
2023-01-18 11:41:18 +01:00 |
|
pcmcia
|
|
|
|
perf
|
perf/smmuv3: Fix hotplug callback leak in arm_smmu_pmu_init()
|
2023-01-18 11:40:50 +01:00 |
|
phy
|
phy: stm32: fix an error code in probe
|
2022-11-25 17:42:03 +01:00 |
|
pinctrl
|
pinctrl: pinconf-generic: add missing of_node_put()
|
2023-01-18 11:41:06 +01:00 |
|
platform
|
platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
|
2023-01-18 11:40:58 +01:00 |
|
pnp
|
PNP: fix name memory leak in pnp_alloc_dev()
|
2023-01-18 11:40:54 +01:00 |
|
power
|
power: supply: fix null pointer dereferencing in power_supply_get_battery_info
|
2023-01-18 11:41:28 +01:00 |
|
powercap
|
powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue
|
2022-10-26 13:22:47 +02:00 |
|
pps
|
|
|
|
ps3
|
|
|
|
ptp
|
|
|
|
pwm
|
pwm: sifive: Call pwm_sifive_update_clock() while mutex is held
|
2023-01-18 11:41:30 +01:00 |
|
rapidio
|
rapidio: devices: fix missing put_device in mport_cdev_open
|
2023-01-18 11:40:59 +01:00 |
|
ras
|
|
|
|
regulator
|
regulator: core: fix deadlock on regulator enable
|
2023-01-18 11:41:41 +01:00 |
|
remoteproc
|
remoteproc: qcom_q6v5_pas: Fix missing of_node_put() in adsp_alloc_memory_region()
|
2023-01-18 11:41:31 +01:00 |
|
reset
|
|
|
|
rpmsg
|
rpmsg: qcom: glink: replace strncpy() with strscpy_pad()
|
2022-10-15 07:54:38 +02:00 |
|
rtc
|
rtc: mxc_v2: Add missing clk_disable_unprepare()
|
2023-01-18 11:41:32 +01:00 |
|
s390
|
s390/lcs: Fix return type of lcs_start_xmit()
|
2023-01-18 11:41:36 +01:00 |
|
sbus
|
|
|
|
scsi
|
scsi: snic: Fix possible UAF in snic_tgt_create()
|
2023-01-18 11:41:20 +01:00 |
|
sfi
|
|
|
|
sh
|
|
|
|
siox
|
siox: fix possible memory leak in siox_device_add()
|
2022-11-25 17:42:14 +01:00 |
|
slimbus
|
slimbus: stream: correct presence rate frequencies
|
2022-11-25 17:42:17 +01:00 |
|
soc
|
soc: ti: knav_qmss_queue: Fix PM disable depth imbalance in knav_queue_probe
|
2023-01-18 11:40:50 +01:00 |
|
soundwire
|
|
|
|
spi
|
spi: spi-gpio: Don't set MOSI as an input if not 3WIRE mode
|
2023-01-18 11:41:12 +01:00 |
|
spmi
|
spmi: pmic-arb: correct duplicate APID to PPID mapping logic
|
2022-10-26 13:22:43 +02:00 |
|
ssb
|
|
|
|
staging
|
staging: rtl8192e: Fix potential use-after-free in rtllib_rx_Monitor()
|
2023-01-18 11:41:25 +01:00 |
|
target
|
scsi: target: tcm_loop: Fix possible name leak in tcm_loop_setup_hba_bus()
|
2022-11-25 17:42:20 +01:00 |
|
tc
|
|
|
|
tee
|
tee: optee: fix possible memory leak in optee_register_device()
|
2022-12-08 11:22:57 +01:00 |
|
thermal
|
thermal: intel_powerclamp: Use first online CPU as control_cpu
|
2022-10-26 13:23:01 +02:00 |
|
thunderbolt
|
thunderbolt: Use the actual buffer in tb_async_error()
|
2022-09-15 12:04:52 +02:00 |
|
tty
|
serial: sunsab: Fix error handling in sunsab_init()
|
2023-01-18 11:41:23 +01:00 |
|
uio
|
uio: uio_dmem_genirq: Fix deadlock between irq config and handling
|
2023-01-18 11:41:22 +01:00 |
|
usb
|
usb: dwc3: core: defer probe on ulpi_read_id timeout
|
2023-01-18 11:41:41 +01:00 |
|
vfio
|
vfio: platform: Do not pass return buffer to ACPI _RST method
|
2023-01-18 11:41:22 +01:00 |
|
vhost
|
vhost/vsock: Use kvmalloc/kvfree for larger packets.
|
2022-10-26 13:22:25 +02:00 |
|
video
|
fbdev: uvesafb: Fixes an error handling path in uvesafb_probe()
|
2023-01-18 11:41:27 +01:00 |
|
virt
|
vboxguest: Do not use devm for irq
|
2022-08-25 11:18:33 +02:00 |
|
virtio
|
|
|
|
visorbus
|
|
|
|
vlynq
|
|
|
|
vme
|
vme: Fix error not catched in fake_init()
|
2023-01-18 11:41:26 +01:00 |
|
w1
|
|
|
|
watchdog
|
|
|
|
xen
|
xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource()
|
2023-01-18 11:40:57 +01:00 |
|
zorro
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|