Skip to content

Commit 1171f32

Browse files
Yongpeng Yanggregkh
authored andcommitted
f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()
[ Upstream commit 2d9c4a4 ] The xfstests case "generic/107" and syzbot have both reported a NULL pointer dereference. The concurrent scenario that triggers the panic is as follows: F2FS_WB_CP_DATA write callback umount - f2fs_write_checkpoint - f2fs_wait_on_all_pages(sbi, F2FS_WB_CP_DATA) - blk_mq_end_request - bio_endio - f2fs_write_end_io : dec_page_count(sbi, F2FS_WB_CP_DATA) : wake_up(&sbi->cp_wait) - kill_f2fs_super - kill_block_super - f2fs_put_super : iput(sbi->node_inode) : sbi->node_inode = NULL : f2fs_in_warm_node_list - is_node_folio // sbi->node_inode is NULL and panic The root cause is that f2fs_put_super() calls iput(sbi->node_inode) and sets sbi->node_inode to NULL after sbi->nr_pages[F2FS_WB_CP_DATA] is decremented to zero. As a result, f2fs_in_warm_node_list() may dereference a NULL node_inode when checking whether a folio belongs to the node inode, leading to a panic. This patch fixes the issue by calling f2fs_in_warm_node_list() before decrementing sbi->nr_pages[F2FS_WB_CP_DATA], thus preventing the use-after-free condition. Cc: stable@kernel.org Fixes: 50fa53e ("f2fs: fix to avoid broken of dnode block list") Reported-by: syzbot+6e4cb1cac5efc96ea0ca@syzkaller.appspotmail.com Signed-off-by: Yongpeng Yang <yangyongpeng@xiaomi.com> Reviewed-by: Chao Yu <chao@kernel.org> Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org> [ folio => page ] Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 8e47d29 commit 1171f32

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

fs/f2fs/data.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -356,6 +356,8 @@ static void f2fs_write_end_io(struct bio *bio)
356356

357357
f2fs_bug_on(sbi, page->mapping == NODE_MAPPING(sbi) &&
358358
page->index != nid_of_node(page));
359+
if (f2fs_in_warm_node_list(sbi, page))
360+
f2fs_del_fsync_node_entry(sbi, page);
359361

360362
dec_page_count(sbi, type);
361363

@@ -367,8 +369,6 @@ static void f2fs_write_end_io(struct bio *bio)
367369
wq_has_sleeper(&sbi->cp_wait))
368370
wake_up(&sbi->cp_wait);
369371

370-
if (f2fs_in_warm_node_list(sbi, page))
371-
f2fs_del_fsync_node_entry(sbi, page);
372372
clear_page_private_gcing(page);
373373
end_page_writeback(page);
374374
}

0 commit comments

Comments
 (0)