Dylan Wolff
0d50231d47
jfs: Fix null-ptr-deref in jfs_ioc_trim
[ Upstream commit a4685408ff6c3e2af366ad9a7274f45ff3f394ee ]
[ Syzkaller Report ]
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000087: 0000 [#1
KASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f]
CPU: 2 UID: 0 PID: 10614 Comm: syz-executor.0 Not tainted
6.13.0-rc6-gfbfd64d25c7a-dirty #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Sched_ext: serialise (enabled+all), task: runnable_at=-30ms
RIP: 0010:jfs_ioc_trim+0x34b/0x8f0
Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93
90 82 fe ff 4c 89 ff 31 f6
RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206
RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a
RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001
RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000
R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438
FS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
? __die_body+0x61/0xb0
? die_addr+0xb1/0xe0
? exc_general_protection+0x333/0x510
? asm_exc_general_protection+0x26/0x30
? jfs_ioc_trim+0x34b/0x8f0
jfs_ioctl+0x3c8/0x4f0
? __pfx_jfs_ioctl+0x10/0x10
? __pfx_jfs_ioctl+0x10/0x10
__se_sys_ioctl+0x269/0x350
? __pfx___se_sys_ioctl+0x10/0x10
? do_syscall_64+0xfb/0x210
do_syscall_64+0xee/0x210
? syscall_exit_to_user_mode+0x1e0/0x330
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe51f4903ad
Code: c3 e8 a7 2b 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48
89 f7 48 89 d6 48 89 ca 4d
RSP: 002b:00007fe5202250c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fe51f5cbf80 RCX: 00007fe51f4903ad
RDX: 0000000020000680 RSI: 00000000c0185879 RDI: 0000000000000005
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007fe520225640
R13: 000000000000000e R14: 00007fe51f44fca0 R15: 00007fe52021d000
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:jfs_ioc_trim+0x34b/0x8f0
Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93
90 82 fe ff 4c 89 ff 31 f6
RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206
RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a
RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001
RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000
R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438
FS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Kernel panic - not syncing: Fatal exception
[ Analysis ]
We believe that we have found a concurrency bug in the `fs/jfs` module
that results in a null pointer dereference. There is a closely related
issue which has been fixed:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d6c1b3599b2feb5c7291f5ac3a36e5fa7cedb234
... but, unfortunately, the accepted patch appears to still be
susceptible to a null pointer dereference under some interleavings.
To trigger the bug, we think that `JFS_SBI(ipbmap->i_sb)->bmap` is set
to NULL in `dbFreeBits` and then dereferenced in `jfs_ioc_trim`. This
bug manifests quite rarely under normal circumstances, but is
triggereable from a syz-program.
Reported-and-tested-by: Dylan J. Wolff<wolffd@comp.nus.edu.sg>
Reported-and-tested-by: Jiacheng Xu <stitch@zju.edu.cn>
Signed-off-by: Dylan J. Wolff<wolffd@comp.nus.edu.sg>
Signed-off-by: Jiacheng Xu <stitch@zju.edu.cn>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2025-06-27 11:02:54 +01:00 |
| .. |
|
9p
|
fs/9p: drop inodes immediately on non-.L too
|
2024-05-17 11:43:53 +02:00 |
|
adfs
|
|
|
|
affs
|
affs: don't write overlarge OFS data block size fields
|
2025-04-10 14:29:42 +02:00 |
|
afs
|
afs: Fix directory format encoding struct
|
2025-03-13 12:42:52 +01:00 |
|
autofs
|
autofs: fix memory leak of waitqueues in autofs_catatonic_mode
|
2023-09-23 11:00:02 +02:00 |
|
befs
|
|
|
|
bfs
|
|
|
|
btrfs
|
btrfs: send: return -ENAMETOOLONG when attempting a path that is too long
|
2025-06-04 14:32:30 +02:00 |
|
cachefiles
|
cachefiles: fix memory leak in cachefiles_add_cache()
|
2024-03-06 14:36:10 +00:00 |
|
ceph
|
ceph: remove the incorrect Fw reference check when dirtying pages
|
2024-11-08 16:20:35 +01:00 |
|
cifs
|
smb: client: Reset all search buffer pointers when releasing buffer
|
2025-06-04 14:32:36 +02:00 |
|
coda
|
|
|
|
configfs
|
configfs: Do not override creating attribute file failure in populate_attrs()
|
2025-06-27 11:02:50 +01:00 |
|
cramfs
|
|
|
|
crypto
|
|
|
|
debugfs
|
new helper: lookup_positive_unlocked()
|
2023-09-23 10:59:40 +02:00 |
|
devpts
|
|
|
|
dlm
|
dlm: fix plock lookup when using multiple lockspaces
|
2023-09-23 10:59:55 +02:00 |
|
ecryptfs
|
ecryptfs: Fix buffer size for tag 66 packet
|
2024-06-16 13:28:32 +02:00 |
|
efivarfs
|
efivarfs: Fix error on non-existent file
|
2025-01-09 13:23:28 +01:00 |
|
efs
|
|
|
|
erofs
|
erofs: fix incorrect symlink detection in fast symlink
|
2025-01-09 13:23:27 +01:00 |
|
exportfs
|
|
|
|
ext2
|
ext2: fix datatype of block number in ext2_xattr_set2()
|
2023-09-23 11:00:04 +02:00 |
|
ext4
|
ext4: fix calculation of credits for extent tree modification
|
2025-06-27 11:02:51 +01:00 |
|
f2fs
|
f2fs: prevent kernel warning due to negative i_nlink from corrupted image
|
2025-06-27 11:02:51 +01:00 |
|
fat
|
fat: fix uninitialized variable
|
2024-11-08 16:20:47 +01:00 |
|
freevxfs
|
|
|
|
fscache
|
|
|
|
fuse
|
virtiofs: add filesystem context source name check
|
2025-05-02 07:39:21 +02:00 |
|
gfs2
|
gfs2: move msleep to sleepable context
|
2025-06-27 11:02:50 +01:00 |
|
hfs
|
hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key
|
2025-05-02 07:39:20 +02:00 |
|
hfsplus
|
hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key
|
2025-05-02 07:39:20 +02:00 |
|
hostfs
|
|
|
|
hpfs
|
|
|
|
hugetlbfs
|
fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super
|
2024-03-06 14:36:10 +00:00 |
|
iomap
|
iomap: Set all uptodate bits for an Uptodate page
|
2024-03-01 13:13:35 +01:00 |
|
isofs
|
isofs: Prevent the use of too small fid
|
2025-05-02 07:39:20 +02:00 |
|
jbd2
|
jbd2: remove wrong sb->s_sequence check
|
2025-05-02 07:39:15 +02:00 |
|
jffs2
|
jffs2: Fix rtime decompressor
|
2024-12-14 19:44:56 +01:00 |
|
jfs
|
jfs: Fix null-ptr-deref in jfs_ioc_trim
|
2025-06-27 11:02:54 +01:00 |
|
kernfs
|
fs/kernfs/dir: obey S_ISGID
|
2024-02-23 08:25:03 +01:00 |
|
lockd
|
fs: lockd: avoid possible wrong NULL parameter
|
2023-09-23 10:59:48 +02:00 |
|
minix
|
|
|
|
nfs
|
nfs: don't share pNFS DS connections between net namespaces
|
2025-06-04 14:32:37 +02:00 |
|
nfs_common
|
|
|
|
nfsd
|
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
|
2025-06-27 11:02:51 +01:00 |
|
nilfs2
|
nilfs2: do not propagate ENOENT error from nilfs_btree_propagate()
|
2025-06-27 11:02:47 +01:00 |
|
nls
|
fs/nls: make load_nls() take a const parameter
|
2023-09-23 10:59:38 +02:00 |
|
notify
|
fanotify: disallow mount/sb marks on kernel internal pseudo fs
|
2023-07-27 08:37:26 +02:00 |
|
ntfs
|
|
|
|
ocfs2
|
ocfs2: stop quota recovery before disabling quotas
|
2025-06-04 14:32:27 +02:00 |
|
omfs
|
|
|
|
openpromfs
|
openpromfs: finish conversion to the new mount API
|
2024-06-16 13:28:32 +02:00 |
|
orangefs
|
orangefs: Do not truncate file size
|
2025-06-04 14:32:32 +02:00 |
|
overlayfs
|
ovl: Filter invalid inodes with missing lookup function
|
2024-12-14 19:44:43 +01:00 |
|
proc
|
fs/procfs: fix the comment above proc_pid_wchan()
|
2025-04-10 14:29:42 +02:00 |
|
pstore
|
pstore/ram: Fix crash when setting number of cpus to an odd number
|
2024-02-23 08:24:55 +01:00 |
|
qnx4
|
|
|
|
qnx6
|
|
|
|
quota
|
quota: flush quota_release_work upon quota writeback
|
2024-12-14 19:44:42 +01:00 |
|
ramfs
|
|
|
|
reiserfs
|
reiserfs: Check the return value from __getblk()
|
2023-09-23 10:59:40 +02:00 |
|
romfs
|
|
|
|
squashfs
|
Squashfs: check return result of sb_min_blocksize
|
2025-06-27 11:02:47 +01:00 |
|
sysfs
|
fs: sysfs: Fix reference leak in sysfs_break_active_protection()
|
2024-05-02 16:18:32 +02:00 |
|
sysv
|
sysv: don't call sb_bread() with pointers_lock held
|
2024-04-13 12:51:38 +02:00 |
|
tracefs
|
tracefs: Add missing lockdown check to tracefs_create_dir()
|
2023-09-23 11:00:06 +02:00 |
|
ubifs
|
ubifs: skip dumping tnc tree when zroot is null
|
2025-03-13 12:42:59 +01:00 |
|
udf
|
udf: Fix use of check_add_overflow() with mixed type arguments
|
2025-03-13 12:42:51 +01:00 |
|
ufs
|
|
|
|
unicode
|
Revert "unicode: Don't special case ignorable code points"
|
2024-12-14 19:44:55 +01:00 |
|
verity
|
fsverity: skip PKCS#7 parser when keyring is empty
|
2023-09-23 10:59:55 +02:00 |
|
xfs
|
xfs: don't drop errno values when we fail to ficlone the entire range
|
2024-12-19 18:05:03 +01:00 |
|
aio.c
|
fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion
|
2024-04-13 12:51:29 +02:00 |
|
anon_inodes.c
|
|
|
|
attr.c
|
attr: block mode changes of symlinks
|
2023-09-23 11:00:06 +02:00 |
|
bad_inode.c
|
|
|
|
binfmt_aout.c
|
|
|
|
binfmt_elf.c
|
|
|
|
binfmt_elf_fdpic.c
|
fs: binfmt_elf_efpic: don't use missing interpreter's properties
|
2024-09-04 13:14:54 +02:00 |
|
binfmt_em86.c
|
|
|
|
binfmt_flat.c
|
binfmt_flat: Fix integer overflow bug on 32 bit systems
|
2025-03-13 12:43:07 +01:00 |
|
binfmt_misc.c
|
binfmt_misc: cleanup on filesystem umount
|
2024-09-04 13:14:53 +02:00 |
|
binfmt_script.c
|
|
|
|
block_dev.c
|
block: Don't invalidate pagecache for invalid falloc modes
|
2024-01-08 11:29:48 +01:00 |
|
buffer.c
|
|
|
|
char_dev.c
|
|
|
|
compat.c
|
|
|
|
compat_binfmt_elf.c
|
|
|
|
compat_ioctl.c
|
lsm: new security_file_ioctl_compat() hook
|
2024-02-23 08:25:15 +01:00 |
|
coredump.c
|
coredump: hand a pidfd to the usermode coredump helper
|
2025-06-04 14:32:36 +02:00 |
|
d_path.c
|
|
|
|
dax.c
|
|
|
|
dcache.c
|
fs: better handle deep ancestor chains in is_subdir()
|
2024-07-27 10:38:32 +02:00 |
|
dcookies.c
|
|
|
|
direct-io.c
|
|
|
|
drop_caches.c
|
|
|
|
eventfd.c
|
eventfd: prevent underflow for eventfd semaphores
|
2023-09-23 10:59:40 +02:00 |
|
eventpoll.c
|
epoll: Add synchronous wakeup support for ep_poll_callback
|
2025-01-09 13:23:32 +01:00 |
|
exec.c
|
parisc: Fix stack start for ADDR_NO_RANDOMIZE personality
|
2024-11-08 16:20:40 +01:00 |
|
fcntl.c
|
fs: Fix file_set_fowner LSM hook inconsistencies
|
2024-11-08 16:20:34 +01:00 |
|
fhandle.c
|
do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
|
2024-03-26 18:22:13 -04:00 |
|
file.c
|
fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
|
2024-09-04 13:14:50 +02:00 |
|
file_table.c
|
|
|
|
filesystems.c
|
fs/filesystems: Fix potential unsigned integer underflow in fs_name()
|
2025-06-27 11:02:50 +01:00 |
|
fs-writeback.c
|
|
|
|
fs_context.c
|
fs: avoid empty option when generating legacy mount string
|
2023-07-27 08:37:25 +02:00 |
|
fs_parser.c
|
|
|
|
fs_pin.c
|
|
|
|
fs_struct.c
|
|
|
|
fs_types.c
|
|
|
|
fsopen.c
|
|
|
|
inode.c
|
vfs: fix race between evice_inodes() and find_inode()&iput()
|
2024-11-08 16:20:34 +01:00 |
|
internal.h
|
fs: Establish locking order for unrelated directories
|
2023-07-27 08:37:26 +02:00 |
|
io_uring.c
|
io_uring: fail NOP if non-zero op flags is passed in
|
2024-06-16 13:28:48 +02:00 |
|
ioctl.c
|
|
|
|
Kconfig
|
nfs: add missing selections of CONFIG_CRC32
|
2025-05-02 07:39:20 +02:00 |
|
Kconfig.binfmt
|
|
|
|
libfs.c
|
|
|
|
locks.c
|
filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
|
2024-09-04 13:15:02 +02:00 |
|
Makefile
|
|
|
|
mbcache.c
|
|
|
|
mount.h
|
|
|
|
mpage.c
|
|
|
|
namei.c
|
fuse: don't truncate cached, mutated symlink
|
2025-04-10 14:29:36 +02:00 |
|
namespace.c
|
do_change_type(): refuse to operate on unmounted/not ours mounts
|
2025-06-27 11:02:49 +01:00 |
|
no-block.c
|
|
|
|
nsfs.c
|
|
|
|
open.c
|
ftruncate: pass a signed offset
|
2024-07-05 09:08:31 +02:00 |
|
pipe.c
|
|
|
|
pnode.c
|
|
|
|
pnode.h
|
|
|
|
posix_acl.c
|
|
|
|
proc_namespace.c
|
|
|
|
read_write.c
|
|
|
|
readdir.c
|
|
|
|
select.c
|
fs/select: rework stack allocation hack for clang
|
2024-03-26 18:22:13 -04:00 |
|
seq_file.c
|
|
|
|
signalfd.c
|
|
|
|
splice.c
|
|
|
|
stack.c
|
|
|
|
stat.c
|
|
|
|
statfs.c
|
|
|
|
super.c
|
fs: explicitly unregister per-superblock BDIs
|
2024-11-08 16:20:26 +01:00 |
|
sync.c
|
ovl: skip overlayfs superblocks at global sync
|
2023-12-08 08:44:27 +01:00 |
|
timerfd.c
|
|
|
|
userfaultfd.c
|
|
|
|
utimes.c
|
|
|
|
xattr.c
|
|
|