No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Sagi Grimberg 70356b756a nvme: fix a possible use-after-free in controller reset during load
[ Upstream commit 0fa0f99fc84e41057cbdd2efbfe91c6b2f47dd9d ]

Unlike .queue_rq, in .submit_async_event drivers may not check the ctrl
readiness for AER submission. This may lead to a use-after-free
condition that was observed with nvme-tcp.

The race condition may happen in the following scenario:
1. driver executes its reset_ctrl_work
2. -> nvme_stop_ctrl - flushes ctrl async_event_work
3. ctrl sends AEN which is received by the host, which in turn
   schedules AEN handling
4. teardown admin queue (which releases the queue socket)
5. AEN processed, submits another AER, calling the driver to submit
6. driver attempts to send the cmd
==> use-after-free

In order to fix that, add ctrl state check to validate the ctrl
is actually able to accept the AER submission.

This addresses the above race in controller resets because the driver
during teardown should:
1. change ctrl state to RESETTING
2. flush async_event_work (as well as other async work elements)

So after 1,2, any other AER command will find the
ctrl state to be RESETTING and bail out without submitting the AER.

Signed-off-by: Sagi Grimberg <sagi@grimberg.me>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-02-23 11:59:55 +01:00
arch parisc: Drop __init from map_pages declaration 2022-02-23 11:59:54 +01:00
block block: bio-integrity: Advance seed correctly for larger interval sizes 2022-02-08 18:24:28 +01:00
certs
crypto
Documentation bpf: Add kconfig knob for disabling unpriv bpf by default 2022-02-16 12:52:49 +01:00
drivers nvme: fix a possible use-after-free in controller reset during load 2022-02-23 11:59:55 +01:00
fs quota: make dquot_quota_sync return errors from ->sync_fs 2022-02-23 11:59:55 +01:00
include net: fix a memleak when uncloning an skb dst and its metadata 2022-02-16 12:52:51 +01:00
init bpf: Add kconfig knob for disabling unpriv bpf by default 2022-02-16 12:52:49 +01:00
ipc
kernel perf: Fix list corruption in perf_cgroup_switch() 2022-02-16 12:52:53 +01:00
lib
LICENSES
mm mm/kmemleak: avoid scanning potential huge holes 2022-02-08 18:24:28 +01:00
net ax25: improve the incomplete fix to avoid UAF and NPD bugs 2022-02-23 11:59:55 +01:00
samples
scripts Makefile.extrawarn: Move -Wunaligned-access to W=1 2022-02-23 11:59:54 +01:00
security ima: Do not print policy rule with inactive LSM labels 2022-02-16 12:52:47 +01:00
sound ASoC: max9759: fix underflow in speaker_gain_control_put() 2022-02-08 18:24:33 +01:00
tools selftests/zram: Adapt the situation that /dev/zram0 is being used 2022-02-23 11:59:55 +01:00
usr
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile Linux 5.4.180 2022-02-16 12:52:54 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.