Baokun Li
455f4a2349
jffs2: fix memory leak in jffs2_scan_medium
commit 9cdd3128874f5fe759e2c4e1360ab7fb96a8d1df upstream.
If an error is returned in jffs2_scan_eraseblock() and some memory
has been added to the jffs2_summary *s, we can observe the following
kmemleak report:
--------------------------------------------
unreferenced object 0xffff88812b889c40 (size 64):
comm "mount", pid 692, jiffies 4294838325 (age 34.288s)
hex dump (first 32 bytes):
40 48 b5 14 81 88 ff ff 01 e0 31 00 00 00 50 00 @H........1...P.
00 00 01 00 00 00 01 00 00 00 02 00 00 00 09 08 ................
backtrace:
[<ffffffffae93a3a3>] __kmalloc+0x613/0x910
[<ffffffffaf423b9c>] jffs2_sum_add_dirent_mem+0x5c/0xa0
[<ffffffffb0f3afa8>] jffs2_scan_medium.cold+0x36e5/0x4794
[<ffffffffb0f3dbe1>] jffs2_do_mount_fs.cold+0xa7/0x2267
[<ffffffffaf40acf3>] jffs2_do_fill_super+0x383/0xc30
[<ffffffffaf40c00a>] jffs2_fill_super+0x2ea/0x4c0
[<ffffffffb0315d64>] mtd_get_sb+0x254/0x400
[<ffffffffb0315f5f>] mtd_get_sb_by_nr+0x4f/0xd0
[<ffffffffb0316478>] get_tree_mtd+0x498/0x840
[<ffffffffaf40bd15>] jffs2_get_tree+0x25/0x30
[<ffffffffae9f358d>] vfs_get_tree+0x8d/0x2e0
[<ffffffffaea7a98f>] path_mount+0x50f/0x1e50
[<ffffffffaea7c3d7>] do_mount+0x107/0x130
[<ffffffffaea7c5c5>] __se_sys_mount+0x1c5/0x2f0
[<ffffffffaea7c917>] __x64_sys_mount+0xc7/0x160
[<ffffffffb10142f5>] do_syscall_64+0x45/0x70
unreferenced object 0xffff888114b54840 (size 32):
comm "mount", pid 692, jiffies 4294838325 (age 34.288s)
hex dump (first 32 bytes):
c0 75 b5 14 81 88 ff ff 02 e0 02 00 00 00 02 00 .u..............
00 00 84 00 00 00 44 00 00 00 6b 6b 6b 6b 6b a5 ......D...kkkkk.
backtrace:
[<ffffffffae93be24>] kmem_cache_alloc_trace+0x584/0x880
[<ffffffffaf423b04>] jffs2_sum_add_inode_mem+0x54/0x90
[<ffffffffb0f3bd44>] jffs2_scan_medium.cold+0x4481/0x4794
[...]
unreferenced object 0xffff888114b57280 (size 32):
comm "mount", pid 692, jiffies 4294838393 (age 34.357s)
hex dump (first 32 bytes):
10 d5 6c 11 81 88 ff ff 08 e0 05 00 00 00 01 00 ..l.............
00 00 38 02 00 00 28 00 00 00 6b 6b 6b 6b 6b a5 ..8...(...kkkkk.
backtrace:
[<ffffffffae93be24>] kmem_cache_alloc_trace+0x584/0x880
[<ffffffffaf423c34>] jffs2_sum_add_xattr_mem+0x54/0x90
[<ffffffffb0f3a24f>] jffs2_scan_medium.cold+0x298c/0x4794
[...]
unreferenced object 0xffff8881116cd510 (size 16):
comm "mount", pid 692, jiffies 4294838395 (age 34.355s)
hex dump (first 16 bytes):
00 00 00 00 00 00 00 00 09 e0 60 02 00 00 6b a5 ..........`...k.
backtrace:
[<ffffffffae93be24>] kmem_cache_alloc_trace+0x584/0x880
[<ffffffffaf423cc4>] jffs2_sum_add_xref_mem+0x54/0x90
[<ffffffffb0f3b2e3>] jffs2_scan_medium.cold+0x3a20/0x4794
[...]
--------------------------------------------
Therefore, we should call jffs2_sum_reset_collected(s) on exit to
release the memory added in s. In addition, a new tag "out_buf" is
added to prevent the NULL pointer reference caused by s being NULL.
(thanks to Zhang Yi for this analysis)
Fixes: e631ddba58 ("[JFFS2] Add erase block summary support (mount time improvement)")
Cc: stable@vger.kernel.org
Co-developed-with: Zhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2022-04-15 14:17:59 +02:00 |
| .. |
|
9p
|
9P: Cast to loff_t before multiplying
|
2020-11-05 11:43:34 +01:00 |
|
adfs
|
|
|
|
affs
|
fs/affs: release old buffer head on error path
|
2021-03-04 10:26:48 +01:00 |
|
afs
|
afs: Fix incorrect triggering of sillyrename on 3rd-party invalidation
|
2021-09-30 10:09:22 +02:00 |
|
autofs
|
|
|
|
befs
|
|
|
|
bfs
|
bfs: don't use WARNING: string when it's just info.
|
2021-01-06 14:48:39 +01:00 |
|
btrfs
|
btrfs: add missing run of delayed items after unlink during log replay
|
2022-03-08 19:07:50 +01:00 |
|
cachefiles
|
cachefiles: Handle readpage error correctly
|
2020-11-05 11:43:36 +01:00 |
|
ceph
|
ceph: fix handling of "meta" errors
|
2021-10-27 09:54:27 +02:00 |
|
cifs
|
cifs: fix double free race when mount fails in cifs_get_root()
|
2022-03-08 19:07:45 +01:00 |
|
coda
|
|
|
|
configfs
|
configfs: fix a race in configfs_{,un}register_subsystem()
|
2022-03-02 11:41:10 +01:00 |
|
cramfs
|
|
|
|
crypto
|
fscrypt: add fscrypt_symlink_getattr() for computing st_size
|
2021-09-12 08:56:38 +02:00 |
|
debugfs
|
debugfs: lockdown: Allow reading debugfs files that are not world readable
|
2022-01-27 09:19:36 +01:00 |
|
devpts
|
fsnotify: fix fsnotify hooks in pseudo filesystems
|
2022-02-01 17:24:34 +01:00 |
|
dlm
|
fs: dlm: filter user dlm messages for kernel locks
|
2022-01-27 09:19:40 +01:00 |
|
ecryptfs
|
Revert "ecryptfs: replace BUG_ON with error handling code"
|
2021-05-26 12:05:19 +02:00 |
|
efivarfs
|
efivarfs: revert "fix memory leak in efivarfs_create()"
|
2020-12-02 08:49:53 +01:00 |
|
efs
|
|
|
|
erofs
|
erofs: fix unsafe pagevec reuse of hooked pclusters
|
2021-11-21 13:38:51 +01:00 |
|
exportfs
|
|
|
|
ext2
|
ext2: fix sleeping in atomic bugs on error
|
2021-10-09 14:39:49 +02:00 |
|
ext4
|
ext4: add check to prevent attempting to resize an fs with sparse_super2
|
2022-03-16 13:21:48 +01:00 |
|
f2fs
|
f2fs: fix to do sanity check on .cp_pack_total_block_count
|
2022-04-15 14:17:59 +02:00 |
|
fat
|
fat: don't allow to mount if the FAT length == 0
|
2020-06-17 16:40:36 +02:00 |
|
freevxfs
|
|
|
|
fscache
|
fscache: Fix cookie key hashing
|
2021-09-22 12:26:25 +02:00 |
|
fuse
|
fuse: fix pipe buffer lifetime for direct_io
|
2022-03-16 13:21:47 +01:00 |
|
gfs2
|
gfs2: Fix length of holes reported at end-of-file
|
2021-12-08 09:01:08 +01:00 |
|
hfs
|
hfs: add lock nesting notation to hfs_find_init
|
2021-07-31 08:19:38 +02:00 |
|
hfsplus
|
hfsplus: prevent corruption in shrinking truncate
|
2021-05-19 10:08:29 +02:00 |
|
hostfs
|
hostfs: fix memory handling in follow_link()
|
2021-04-14 08:24:14 +02:00 |
|
hpfs
|
|
|
|
hugetlbfs
|
hugetlbfs: fix mount mode command line processing
|
2021-07-28 13:31:01 +02:00 |
|
iomap
|
mm/swap: consider max pages in iomap_swapfile_add_extent
|
2021-09-15 09:47:35 +02:00 |
|
isofs
|
isofs: Fix out of bound access for corrupted isofs image
|
2021-11-12 14:43:03 +01:00 |
|
jbd2
|
jbd2: fix up sparse warnings in checkpoint code
|
2020-11-18 19:20:30 +01:00 |
|
jffs2
|
jffs2: fix memory leak in jffs2_scan_medium
|
2022-04-15 14:17:59 +02:00 |
|
jfs
|
JFS: fix memleak in jfs_mount
|
2021-11-17 09:48:42 +01:00 |
|
kernfs
|
kernfs: do not call fsnotify() with name without a parent
|
2020-08-19 08:16:12 +02:00 |
|
lockd
|
lockd: lockd server-side shouldn't set fl_ops
|
2021-09-22 12:26:34 +02:00 |
|
minix
|
fs/minix: remove expected error message in block_to_path()
|
2020-08-21 13:05:37 +02:00 |
|
nfs
|
NFS: Do not report writeback errors in nfs_getattr()
|
2022-02-23 11:59:59 +01:00 |
|
nfs_common
|
nfs_common: need lock during iterate through the list
|
2020-12-30 11:51:22 +01:00 |
|
nfsd
|
NFSD: prevent underflow in nfssvc_decode_writeargs()
|
2022-04-15 14:17:59 +02:00 |
|
nilfs2
|
nilfs2: fix memory leak in nilfs_sysfs_delete_snapshot_group
|
2021-09-26 14:07:13 +02:00 |
|
nls
|
|
|
|
notify
|
fanotify: fix ignore mask logic for events on child and on dir
|
2020-06-17 16:40:24 +02:00 |
|
ntfs
|
ntfs: fix ntfs_test_inode and ntfs_init_locked_inode function type
|
2021-12-14 14:48:58 +01:00 |
|
ocfs2
|
ocfs2: fix crash when initialize filecheck kobj fails
|
2022-03-23 09:12:06 +01:00 |
|
omfs
|
|
|
|
openpromfs
|
|
|
|
orangefs
|
orangefs: Fix the size of a memory allocation in orangefs_bufmap_alloc()
|
2022-01-20 09:19:17 +01:00 |
|
overlayfs
|
ovl: fix warning in ovl_create_real()
|
2021-12-22 09:29:40 +01:00 |
|
proc
|
proc/vmcore: fix clearing user buffer by properly using clear_user()
|
2021-12-01 09:23:31 +01:00 |
|
pstore
|
pstore: Fix typo in compression option name
|
2021-03-04 10:26:45 +01:00 |
|
qnx4
|
qnx4: work around gcc false positive warning bug
|
2021-09-30 10:09:26 +02:00 |
|
qnx6
|
|
|
|
quota
|
quota: make dquot_quota_sync return errors from ->sync_fs
|
2022-02-23 11:59:55 +01:00 |
|
ramfs
|
ramfs: fix nommu mmap with gaps in the page cache
|
2020-10-29 09:57:53 +01:00 |
|
reiserfs
|
reiserfs: check directory items on read from disk
|
2021-08-12 13:21:05 +02:00 |
|
romfs
|
romfs: fix uninitialized memory leak in romfs_dev_read()
|
2020-08-26 10:40:51 +02:00 |
|
squashfs
|
squashfs: fix divide error in calculate_skip()
|
2021-05-19 10:08:29 +02:00 |
|
sysfs
|
sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output
|
2021-03-07 12:20:48 +01:00 |
|
sysv
|
|
|
|
tracefs
|
tracefs: Set the group ownership in apply_options() not parse_options()
|
2022-03-02 11:41:13 +01:00 |
|
ubifs
|
ubifs: Error path in ubifs_remount_rw() seems to wrongly free write buffers
|
2022-01-27 09:19:49 +01:00 |
|
udf
|
udf: Fix NULL ptr deref when converting from inline format
|
2022-02-01 17:24:34 +01:00 |
|
ufs
|
fs/ufs: avoid potential u32 multiplication overflow
|
2020-08-21 13:05:37 +02:00 |
|
unicode
|
|
|
|
verity
|
fs-verity: fix signed integer overflow with i_size near S64_MAX
|
2021-10-06 15:42:30 +02:00 |
|
xfs
|
xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate
|
2022-01-11 15:23:32 +01:00 |
|
aio.c
|
aio: fix use-after-free due to missing POLLFREE handling
|
2021-12-14 14:49:02 +01:00 |
|
anon_inodes.c
|
|
|
|
attr.c
|
utimes: Clamp the timestamps in notify_change()
|
2020-02-11 04:35:12 -08:00 |
|
bad_inode.c
|
|
|
|
binfmt_aout.c
|
|
|
|
binfmt_elf.c
|
elf: don't use MAP_FIXED_NOREPLACE for elf interpreter mappings
|
2021-10-06 15:42:35 +02:00 |
|
binfmt_elf_fdpic.c
|
|
|
|
binfmt_em86.c
|
|
|
|
binfmt_flat.c
|
binfmt_flat: revert "binfmt_flat: don't offset the data start"
|
2020-09-03 11:26:39 +02:00 |
|
binfmt_misc.c
|
binfmt_misc: fix possible deadlock in bm_register_write
|
2021-03-17 17:03:57 +01:00 |
|
binfmt_script.c
|
|
|
|
block_dev.c
|
block: reexpand iov_iter after read/write
|
2021-05-22 11:38:29 +02:00 |
|
buffer.c
|
fs: Don't invalidate page buffers in block_write_full_page()
|
2020-11-05 11:43:24 +01:00 |
|
char_dev.c
|
|
|
|
compat.c
|
|
|
|
compat_binfmt_elf.c
|
|
|
|
compat_ioctl.c
|
|
|
|
coredump.c
|
coredump: fix core_pattern parse error
|
2020-12-11 13:23:30 +01:00 |
|
d_path.c
|
fs: fix NULL dereference due to data race in prepend_path()
|
2020-10-29 09:57:45 +01:00 |
|
dax.c
|
dax: fix ENOMEM handling in grab_mapping_entry()
|
2021-07-14 16:53:25 +02:00 |
|
dcache.c
|
fix dget_parent() fastpath race
|
2020-10-01 13:17:19 +02:00 |
|
dcookies.c
|
|
|
|
direct-io.c
|
fs: direct-io: fix missing sdio->boundary
|
2021-04-14 08:24:11 +02:00 |
|
drop_caches.c
|
|
|
|
eventfd.c
|
eventfd: track eventfd_signal() recursion depth
|
2020-02-11 04:35:37 -08:00 |
|
eventpoll.c
|
ep_create_wakeup_source(): dentry name can change under you...
|
2020-10-07 08:01:31 +02:00 |
|
exec.c
|
vfs: check fd has read access in kernel_read_file_from_fd()
|
2021-10-27 09:54:27 +02:00 |
|
fcntl.c
|
fcntl: fix potential deadlock for &fasync_struct.fa_lock
|
2021-09-15 09:47:28 +02:00 |
|
fhandle.c
|
|
|
|
file.c
|
fget: clarify and improve __fget_files() implementation
|
2022-03-02 11:41:18 +01:00 |
|
file_table.c
|
|
|
|
filesystems.c
|
fs/filesystems.c: downgrade user-reachable WARN_ONCE() to pr_warn_once()
|
2020-04-17 10:50:21 +02:00 |
|
fs-writeback.c
|
writeback: fix obtain a reference to a freeing memcg css
|
2021-07-14 16:53:35 +02:00 |
|
fs_context.c
|
memcg: charge fs_context and legacy_fs_context
|
2022-02-08 18:24:29 +01:00 |
|
fs_parser.c
|
|
|
|
fs_pin.c
|
|
|
|
fs_struct.c
|
|
|
|
fs_types.c
|
|
|
|
fsopen.c
|
|
|
|
inode.c
|
futex: Fix inode life-time issue
|
2020-03-25 08:25:58 +01:00 |
|
internal.h
|
cgroup1: fix leaked context root causing sporadic NULL deref in LTP
|
2021-07-31 08:19:37 +02:00 |
|
io_uring.c
|
io_uring: Fix current->fs handling in io_sq_wq_submit_work()
|
2021-01-30 13:54:10 +01:00 |
|
ioctl.c
|
|
|
|
Kconfig
|
|
|
|
Kconfig.binfmt
|
|
|
|
libfs.c
|
libfs: fix error cast of negative value in simple_attr_write()
|
2020-11-24 13:29:19 +01:00 |
|
locks.c
|
locks: reinstate locks_delete_block optimization
|
2020-03-25 08:25:41 +01:00 |
|
Makefile
|
|
|
|
mbcache.c
|
|
|
|
mount.h
|
|
|
|
mpage.c
|
|
|
|
namei.c
|
fsnotify: invalidate dcache before IN_DELETE event
|
2022-02-01 17:24:39 +01:00 |
|
namespace.c
|
fs: warn about impending deprecation of mandatory locks
|
2021-08-26 08:36:22 -04:00 |
|
no-block.c
|
|
|
|
nsfs.c
|
|
|
|
open.c
|
cifs_atomic_open(): fix double-put on late allocation failure
|
2020-03-18 07:17:51 +01:00 |
|
pipe.c
|
pipe: increase minimum default pipe size to 2 pages
|
2021-08-12 13:21:02 +02:00 |
|
pnode.c
|
propagate_one(): mnt_set_mountpoint() needs mount_lock
|
2020-05-02 08:48:44 +02:00 |
|
pnode.h
|
mount: fix mounting of detached mounts onto targets that reside on shared mounts
|
2021-03-17 17:03:33 +01:00 |
|
posix_acl.c
|
|
|
|
proc_namespace.c
|
|
|
|
read_write.c
|
fs: allow deduplication of eof block into the end of the destination file
|
2020-02-11 04:35:23 -08:00 |
|
readdir.c
|
readdir: make sure to verify directory entry for legacy interfaces too
|
2021-04-21 12:56:16 +02:00 |
|
select.c
|
select: Fix indefinitely sleeping task in poll_schedule_timeout()
|
2022-01-29 10:25:11 +01:00 |
|
seq_file.c
|
seq_file: disallow extremely large seq buffer allocations
|
2021-07-20 16:10:54 +02:00 |
|
signalfd.c
|
signalfd: use wake_up_pollfree()
|
2021-12-14 14:49:02 +01:00 |
|
splice.c
|
|
|
|
stack.c
|
|
|
|
stat.c
|
|
|
|
statfs.c
|
|
|
|
super.c
|
vfs: make freeze_super abort when sync_filesystem returns error
|
2022-02-23 11:59:55 +01:00 |
|
sync.c
|
|
|
|
timerfd.c
|
|
|
|
userfaultfd.c
|
userfaultfd: prevent concurrent API initialization
|
2021-09-22 12:26:26 +02:00 |
|
utimes.c
|
utimes: Clamp the timestamps in notify_change()
|
2020-02-11 04:35:12 -08:00 |
|
xattr.c
|
xattr: break delegations in {set,remove}xattr
|
2020-08-11 15:33:39 +02:00 |