android_kernel_motorola_sm6375/drivers
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Mikulas Patocka 384ef33d37 md: fix a crash in mempool_free
commit 341097ee53573e06ab9fc675d96a052385b851fa upstream.

There's a crash in mempool_free when running the lvm test
shell/lvchange-rebuild-raid.sh.

The reason for the crash is this:
* super_written calls atomic_dec_and_test(&mddev->pending_writes) and
  wake_up(&mddev->sb_wait). Then it calls rdev_dec_pending(rdev, mddev)
  and bio_put(bio).
* so, the process that waited on sb_wait and that is woken up is racing
  with bio_put(bio).
* if the process wins the race, it calls bioset_exit before bio_put(bio)
  is executed.
* bio_put(bio) attempts to free a bio into a destroyed bio set - causing
  a crash in mempool_free.

We fix this bug by moving bio_put before atomic_dec_and_test.

We also move rdev_dec_pending before atomic_dec_and_test as suggested by
Neil Brown.

The function md_end_flush has a similar bug - we must call bio_put before
we decrement the number of in-progress bios.

 BUG: kernel NULL pointer dereference, address: 0000000000000000
 #PF: supervisor write access in kernel mode
 #PF: error_code(0x0002) - not-present page
 PGD 11557f0067 P4D 11557f0067 PUD 0
 Oops: 0002 [#1] PREEMPT SMP
 CPU: 0 PID: 73 Comm: kworker/0:1 Not tainted 6.1.0-rc3 #5
 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014
 Workqueue: kdelayd flush_expired_bios [dm_delay]
 RIP: 0010:mempool_free+0x47/0x80
 Code: 48 89 ef 5b 5d ff e0 f3 c3 48 89 f7 e8 32 45 3f 00 48 63 53 08 48 89 c6 3b 53 04 7d 2d 48 8b 43 10 8d 4a 01 48 89 df 89 4b 08 <48> 89 2c d0 e8 b0 45 3f 00 48 8d 7b 30 5b 5d 31 c9 ba 01 00 00 00
 RSP: 0018:ffff88910036bda8 EFLAGS: 00010093
 RAX: 0000000000000000 RBX: ffff8891037b65d8 RCX: 0000000000000001
 RDX: 0000000000000000 RSI: 0000000000000202 RDI: ffff8891037b65d8
 RBP: ffff8891447ba240 R08: 0000000000012908 R09: 00000000003d0900
 R10: 0000000000000000 R11: 0000000000173544 R12: ffff889101a14000
 R13: ffff8891562ac300 R14: ffff889102b41440 R15: ffffe8ffffa00d05
 FS:  0000000000000000(0000) GS:ffff88942fa00000(0000) knlGS:0000000000000000
 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
 CR2: 0000000000000000 CR3: 0000001102e99000 CR4: 00000000000006b0
 Call Trace:
  <TASK>
  clone_endio+0xf4/0x1c0 [dm_mod]
  clone_endio+0xf4/0x1c0 [dm_mod]
  __submit_bio+0x76/0x120
  submit_bio_noacct_nocheck+0xb6/0x2a0
  flush_expired_bios+0x28/0x2f [dm_delay]
  process_one_work+0x1b4/0x300
  worker_thread+0x45/0x3e0
  ? rescuer_thread+0x380/0x380
  kthread+0xc2/0x100
  ? kthread_complete_and_exit+0x20/0x20
  ret_from_fork+0x1f/0x30
  </TASK>
 Modules linked in: brd dm_delay dm_raid dm_mod af_packet uvesafb cfbfillrect cfbimgblt cn cfbcopyarea fb font fbdev tun autofs4 binfmt_misc configfs ipv6 virtio_rng virtio_balloon rng_core virtio_net pcspkr net_failover failover qemu_fw_cfg button mousedev raid10 raid456 libcrc32c async_raid6_recov async_memcpy async_pq raid6_pq async_xor xor async_tx raid1 raid0 md_mod sd_mod t10_pi crc64_rocksoft crc64 virtio_scsi scsi_mod evdev psmouse bsg scsi_common [last unloaded: brd]
 CR2: 0000000000000000
 ---[ end trace 0000000000000000 ]---

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Song Liu <song@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-01-18 11:41:44 +01:00
..
accessibility
acpi ACPICA: Fix error code path in acpi_ds_call_control_method() 2023-01-18 11:41:34 +01:00
amba
android binder: Gracefully handle BINDER_TYPE_FDA objects with num_fds=0 2022-12-08 11:23:01 +01:00
ata ata: ahci: Fix PCS quirk application for suspend 2023-01-18 11:41:42 +01:00
atm
auxdisplay
base class: fix possible memory leak in __class_register() 2023-01-18 11:41:21 +01:00
bcma
block drbd: use after free in drbd_create_device() 2022-11-25 17:42:16 +01:00
bluetooth Bluetooth: hci_bcsp: don't call kfree_skb() under spin_lock_irqsave() 2023-01-18 11:41:16 +01:00
bus bus: sunxi-rsb: Support atomic transfers 2022-12-08 11:22:57 +01:00
cdrom
char ipmi: fix memleak when unload ipmi driver 2023-01-18 11:41:35 +01:00
clk clk: st: Fix memory leak in st_of_quadfs_setup() 2023-01-18 11:41:38 +01:00
clocksource clocksource/drivers/sh_cmt: Make sure channel clock supply is enabled 2023-01-18 11:40:56 +01:00
connector
counter counter: stm32-lptimer-cnt: fix the check on arr and cmp registers update 2023-01-18 11:41:24 +01:00
cpufreq cpufreq: amd_freq_sensitivity: Add missing pci_dev_put() 2023-01-18 11:40:55 +01:00
cpuidle cpuidle: dt: Return the correct numbers of parsed idle states 2023-01-18 11:40:53 +01:00
crypto crypto: img-hash - Fix variable dereferenced before check 'hdev->req' 2023-01-18 11:41:21 +01:00
dax
dca
devfreq
dio drivers: dio: fix possible memory leak in dio_init() 2023-01-18 11:41:21 +01:00
dma dmaengine: at_hdmac: Check return code of dma_async_device_register 2022-11-25 17:42:10 +01:00
dma-buf udmabuf: Set the DMA mask for the udmabuf device (v2) 2022-09-05 10:27:45 +02:00
edac EDAC/i10nm: fix refcount leak in pci_get_dev_wrapper() 2023-01-18 11:40:55 +01:00
eisa
extcon
firewire
firmware firmware: coreboot: Register bus in module init 2022-12-08 11:23:00 +01:00
fpga
fsi fsi: core: Check error number after calling ida_simple_get 2022-10-26 13:22:41 +02:00
gnss
gpio gpio: amd8111: Fix PCI device reference count leak 2022-12-14 11:30:44 +01:00
gpu drm/sti: Fix return type of sti_{dvo,hda,hdmi}_connector_mode_valid() 2023-01-18 11:41:39 +01:00
greybus
hid HID: plantronics: Additional PIDs for double volume key presses quirk 2023-01-18 11:41:43 +01:00
hsi HSI: omap_ssi_core: Fix error handling in ssi_init() 2023-01-18 11:41:28 +01:00
hv Drivers: hv: vmbus: fix possible memory leak in vmbus_device_register() 2022-12-08 11:22:58 +01:00
hwmon hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() 2022-12-08 11:23:03 +01:00
hwspinlock
hwtracing
i2c i2c: ismt: Fix an out-of-bounds bug in ismt_access() 2023-01-18 11:41:26 +01:00
i3c
ide
idle intel_idle: Disable IBRS during long idle 2022-10-07 09:16:55 +02:00
iio iio: adc128s052: add proper .data members in adc128_of_match table 2023-01-18 11:41:41 +01:00
infiniband RDMA/siw: Fix pointer cast warning 2023-01-18 11:41:29 +01:00
input Input: elants_i2c - properly handle the reset GPIO when power is off 2023-01-18 11:41:03 +01:00
interconnect
iommu iommu/fsl_pamu: Fix resource leak in fsl_pamu_probe() 2023-01-18 11:41:29 +01:00
ipack
irqchip irqchip: gic-pm: Use pm_runtime_resume_and_get() in gic_probe() 2023-01-18 11:40:54 +01:00
isdn mISDN: hfcmulti: don't call dev_kfree_skb/kfree_skb() under spin_lock_irqsave() 2023-01-18 11:41:32 +01:00
leds
lightnvm
macintosh macintosh/macio-adb: check the return value of ioremap() 2023-01-18 11:41:29 +01:00
mailbox mailbox: zynq-ipi: fix error handling while device_register() fails 2023-01-18 11:41:33 +01:00
mcb mcb: mcb-parse: fix error handing in chameleon_parse_gdd() 2023-01-18 11:41:25 +01:00
md md: fix a crash in mempool_free 2023-01-18 11:41:44 +01:00
media media: dvbdev: fix refcnt bug 2023-01-18 11:41:42 +01:00
memory memory: of: Fix refcount leak bug in of_get_ddr_timings() 2022-10-26 13:22:31 +02:00
memstick
message
mfd mfd: sm501: Add check for platform_driver_register() 2022-10-26 13:22:42 +02:00
misc cxl: Fix refcount leak in cxl_calc_capp_routing 2023-01-18 11:41:30 +01:00
mmc mmc: f-sdh30: Add quirks for broken timeout clock capability 2023-01-18 11:41:38 +01:00
mtd mtd: maps: pxa2xx-flash: fix memory leak in probe 2023-01-18 11:41:05 +01:00
mux
net ppp: associate skb with a device at tx 2023-01-18 11:41:37 +01:00
nfc nfc: pn533: Clear nfc_target before being used 2023-01-18 11:41:32 +01:00
ntb
nubus
nvdimm
nvme nvme-pci: fix doorbell buffer value endianness 2023-01-18 11:41:42 +01:00
nvmem
of of: overlay: fix null pointer dereferencing in find_dup_cset_node_entry() and find_dup_cset_prop() 2023-01-18 11:41:14 +01:00
opp
oprofile
parisc parisc: Export iosapic_serial_irq() symbol for serial port driver 2022-11-10 17:57:56 +01:00
parport parport_pc: Avoid FIFO port location truncation 2022-11-25 17:42:14 +01:00
pci PCI: Check for alloc failure in pci_request_irq() 2023-01-18 11:41:18 +01:00
pcmcia
perf perf/smmuv3: Fix hotplug callback leak in arm_smmu_pmu_init() 2023-01-18 11:40:50 +01:00
phy phy: stm32: fix an error code in probe 2022-11-25 17:42:03 +01:00
pinctrl pinctrl: pinconf-generic: add missing of_node_put() 2023-01-18 11:41:06 +01:00
platform platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() 2023-01-18 11:40:58 +01:00
pnp PNP: fix name memory leak in pnp_alloc_dev() 2023-01-18 11:40:54 +01:00
power power: supply: fix null pointer dereferencing in power_supply_get_battery_info 2023-01-18 11:41:28 +01:00
powercap powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue 2022-10-26 13:22:47 +02:00
pps
ps3
ptp
pwm pwm: sifive: Call pwm_sifive_update_clock() while mutex is held 2023-01-18 11:41:30 +01:00
rapidio rapidio: devices: fix missing put_device in mport_cdev_open 2023-01-18 11:40:59 +01:00
ras
regulator regulator: core: fix deadlock on regulator enable 2023-01-18 11:41:41 +01:00
remoteproc remoteproc: qcom_q6v5_pas: Fix missing of_node_put() in adsp_alloc_memory_region() 2023-01-18 11:41:31 +01:00
reset
rpmsg rpmsg: qcom: glink: replace strncpy() with strscpy_pad() 2022-10-15 07:54:38 +02:00
rtc rtc: mxc_v2: Add missing clk_disable_unprepare() 2023-01-18 11:41:32 +01:00
s390 s390/lcs: Fix return type of lcs_start_xmit() 2023-01-18 11:41:36 +01:00
sbus
scsi scsi: snic: Fix possible UAF in snic_tgt_create() 2023-01-18 11:41:20 +01:00
sfi
sh
siox siox: fix possible memory leak in siox_device_add() 2022-11-25 17:42:14 +01:00
slimbus slimbus: stream: correct presence rate frequencies 2022-11-25 17:42:17 +01:00
soc soc: ti: knav_qmss_queue: Fix PM disable depth imbalance in knav_queue_probe 2023-01-18 11:40:50 +01:00
soundwire
spi spi: spi-gpio: Don't set MOSI as an input if not 3WIRE mode 2023-01-18 11:41:12 +01:00
spmi spmi: pmic-arb: correct duplicate APID to PPID mapping logic 2022-10-26 13:22:43 +02:00
ssb
staging staging: rtl8192e: Fix potential use-after-free in rtllib_rx_Monitor() 2023-01-18 11:41:25 +01:00
target scsi: target: tcm_loop: Fix possible name leak in tcm_loop_setup_hba_bus() 2022-11-25 17:42:20 +01:00
tc
tee tee: optee: fix possible memory leak in optee_register_device() 2022-12-08 11:22:57 +01:00
thermal thermal: intel_powerclamp: Use first online CPU as control_cpu 2022-10-26 13:23:01 +02:00
thunderbolt thunderbolt: Use the actual buffer in tb_async_error() 2022-09-15 12:04:52 +02:00
tty serial: sunsab: Fix error handling in sunsab_init() 2023-01-18 11:41:23 +01:00
uio uio: uio_dmem_genirq: Fix deadlock between irq config and handling 2023-01-18 11:41:22 +01:00
usb usb: dwc3: core: defer probe on ulpi_read_id timeout 2023-01-18 11:41:41 +01:00
vfio vfio: platform: Do not pass return buffer to ACPI _RST method 2023-01-18 11:41:22 +01:00
vhost vhost/vsock: Use kvmalloc/kvfree for larger packets. 2022-10-26 13:22:25 +02:00
video fbdev: uvesafb: Fixes an error handling path in uvesafb_probe() 2023-01-18 11:41:27 +01:00
virt vboxguest: Do not use devm for irq 2022-08-25 11:18:33 +02:00
virtio
visorbus
vlynq
vme vme: Fix error not catched in fake_init() 2023-01-18 11:41:26 +01:00
w1
watchdog
xen xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() 2023-01-18 11:40:57 +01:00
zorro
Kconfig
Makefile