Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • L linux
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 0
    • Merge requests 0
  • Deployments
    • Deployments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • Kirill Smelkov
  • linux
  • Repository
  • linux
  • block
  • bdev.c
Find file BlameHistoryPermalink
  • Tetsuo Handa's avatar
    block: genhd: fix double kfree() in __alloc_disk_node() · 06cc978d
    Tetsuo Handa authored Oct 02, 2021
    syzbot is reporting use-after-free read at bdev_free_inode() [1], for
    kfree() from __alloc_disk_node() is called before bdev_free_inode()
    (which is called after RCU grace period) reads bdev->bd_disk and calls
    kfree(bdev->bd_disk).
    
    Fix use-after-free read followed by double kfree() problem
    by making sure that bdev->bd_disk is NULL when calling iput().
    
    Link: https://syzkaller.appspot.com/bug?extid=8281086e8a6fbfbd952a
    
     [1]
    Reported-by: default avatarsyzbot <syzbot+8281086e8a6fbfbd952a@syzkaller.appspotmail.com>
    Signed-off-by: default avatarTetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
    Reviewed-by: default avatarChristoph Hellwig <hch@lst.de>
    Link: https://lore.kernel.org/r/e6dd13c5-8db0-4392-6e78-a42ee5d2a1c4@i-love.sakura.ne.jp
    
    
    Signed-off-by: default avatarJens Axboe <axboe@kernel.dk>
    06cc978d
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7