Baokun Li
e711913463
jffs2: fix memory leak in jffs2_scan_medium
...
commit 9cdd3128874f5fe759e2c4e1360ab7fb96a8d1df upstream.
If an error is returned in jffs2_scan_eraseblock() and some memory
has been added to the jffs2_summary *s, we can observe the following
kmemleak report:
--------------------------------------------
unreferenced object 0xffff88812b889c40 (size 64):
comm "mount", pid 692, jiffies 4294838325 (age 34.288s)
hex dump (first 32 bytes):
40 48 b5 14 81 88 ff ff 01 e0 31 00 00 00 50 00 @H........1...P.
00 00 01 00 00 00 01 00 00 00 02 00 00 00 09 08 ................
backtrace:
[<ffffffffae93a3a3>] __kmalloc+0x613/0x910
[<ffffffffaf423b9c>] jffs2_sum_add_dirent_mem+0x5c/0xa0
[<ffffffffb0f3afa8>] jffs2_scan_medium.cold+0x36e5/0x4794
[<ffffffffb0f3dbe1>] jffs2_do_mount_fs.cold+0xa7/0x2267
[<ffffffffaf40acf3>] jffs2_do_fill_super+0x383/0xc30
[<ffffffffaf40c00a>] jffs2_fill_super+0x2ea/0x4c0
[<ffffffffb0315d64>] mtd_get_sb+0x254/0x400
[<ffffffffb0315f5f>] mtd_get_sb_by_nr+0x4f/0xd0
[<ffffffffb0316478>] get_tree_mtd+0x498/0x840
[<ffffffffaf40bd15>] jffs2_get_tree+0x25/0x30
[<ffffffffae9f358d>] vfs_get_tree+0x8d/0x2e0
[<ffffffffaea7a98f>] path_mount+0x50f/0x1e50
[<ffffffffaea7c3d7>] do_mount+0x107/0x130
[<ffffffffaea7c5c5>] __se_sys_mount+0x1c5/0x2f0
[<ffffffffaea7c917>] __x64_sys_mount+0xc7/0x160
[<ffffffffb10142f5>] do_syscall_64+0x45/0x70
unreferenced object 0xffff888114b54840 (size 32):
comm "mount", pid 692, jiffies 4294838325 (age 34.288s)
hex dump (first 32 bytes):
c0 75 b5 14 81 88 ff ff 02 e0 02 00 00 00 02 00 .u..............
00 00 84 00 00 00 44 00 00 00 6b 6b 6b 6b 6b a5 ......D...kkkkk.
backtrace:
[<ffffffffae93be24>] kmem_cache_alloc_trace+0x584/0x880
[<ffffffffaf423b04>] jffs2_sum_add_inode_mem+0x54/0x90
[<ffffffffb0f3bd44>] jffs2_scan_medium.cold+0x4481/0x4794
[...]
unreferenced object 0xffff888114b57280 (size 32):
comm "mount", pid 692, jiffies 4294838393 (age 34.357s)
hex dump (first 32 bytes):
10 d5 6c 11 81 88 ff ff 08 e0 05 00 00 00 01 00 ..l.............
00 00 38 02 00 00 28 00 00 00 6b 6b 6b 6b 6b a5 ..8...(...kkkkk.
backtrace:
[<ffffffffae93be24>] kmem_cache_alloc_trace+0x584/0x880
[<ffffffffaf423c34>] jffs2_sum_add_xattr_mem+0x54/0x90
[<ffffffffb0f3a24f>] jffs2_scan_medium.cold+0x298c/0x4794
[...]
unreferenced object 0xffff8881116cd510 (size 16):
comm "mount", pid 692, jiffies 4294838395 (age 34.355s)
hex dump (first 16 bytes):
00 00 00 00 00 00 00 00 09 e0 60 02 00 00 6b a5 ..........`...k.
backtrace:
[<ffffffffae93be24>] kmem_cache_alloc_trace+0x584/0x880
[<ffffffffaf423cc4>] jffs2_sum_add_xref_mem+0x54/0x90
[<ffffffffb0f3b2e3>] jffs2_scan_medium.cold+0x3a20/0x4794
[...]
--------------------------------------------
Therefore, we should call jffs2_sum_reset_collected(s) on exit to
release the memory added in s. In addition, a new tag "out_buf" is
added to prevent the NULL pointer reference caused by s being NULL.
(thanks to Zhang Yi for this analysis)
Fixes: e631ddba5887 ("[JFFS2] Add erase block summary support (mount time improvement)")
Cc: stable@vger.kernel.org
Co-developed-with: Zhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-15 14:14:39 +02:00
..
2020-11-05 11:08:53 +01:00
2019-08-06 19:06:49 +02:00
2021-03-04 09:39:55 +01:00
2021-06-30 08:48:14 -04:00
2019-12-13 08:51:01 +01:00
2018-12-01 09:37:27 +01:00
2022-03-16 13:20:28 +01:00
2020-11-05 11:08:54 +01:00
2021-09-26 13:39:48 +02:00
2022-03-08 19:04:06 +01:00
2019-08-06 19:06:51 +02:00
2022-03-02 11:38:13 +01:00
2018-11-13 11:08:55 -08:00
2021-09-22 11:47:56 +02:00
2019-05-08 07:21:48 +02:00
2019-03-23 20:09:59 +01:00
2022-01-27 09:04:23 +01:00
2021-05-26 11:48:34 +02:00
2020-12-02 08:48:12 +01:00
2019-12-05 09:20:32 +01:00
2020-01-27 14:50:02 +01:00
2021-10-09 14:11:03 +02:00
2022-03-16 13:20:28 +01:00
2022-04-15 14:14:39 +02:00
2020-06-22 09:05:08 +02:00
2021-09-22 11:48:02 +02:00
2022-04-15 14:14:37 +02:00
2021-12-08 08:50:11 +01:00
2021-07-31 08:22:38 +02:00
2021-05-22 10:59:45 +02:00
2021-06-03 08:38:12 +02:00
2021-11-12 14:40:50 +01:00
2020-09-03 11:24:24 +02:00
2022-04-15 14:14:39 +02:00
2021-11-26 11:36:12 +01:00
2019-12-13 08:52:43 +01:00
2020-12-30 11:25:59 +01:00
2020-08-21 11:05:38 +02:00
2022-02-23 11:58:40 +01:00
2020-12-30 11:26:02 +01:00
2022-04-15 14:14:39 +02:00
2021-09-26 13:39:49 +02:00
2020-06-30 23:17:00 -04:00
2021-07-20 16:15:39 +02:00
2022-03-23 09:10:44 +01:00
2022-01-27 09:04:13 +01:00
2021-12-22 09:19:04 +01:00
2021-12-01 09:27:39 +01:00
2021-03-04 09:39:54 +01:00
2021-10-06 15:31:20 +02:00
2022-02-23 11:58:38 +01:00
2020-10-30 10:38:21 +01:00
2021-08-12 13:19:44 +02:00
2020-08-26 10:30:59 +02:00
2021-05-22 10:59:45 +02:00
2022-03-23 09:10:42 +01:00
2018-12-17 09:24:30 +01:00
2022-03-02 11:38:17 +01:00
2022-01-27 09:04:30 +01:00
2022-02-08 18:23:03 +01:00
2020-08-21 11:05:38 +02:00
2022-01-11 13:58:49 +01:00
2021-12-14 10:18:07 +01:00
2021-10-06 15:31:24 +02:00
2019-07-03 13:14:44 +02:00
2021-03-17 16:43:51 +01:00
2019-11-06 13:05:37 +01:00
2021-05-22 10:59:49 +02:00
2020-11-05 11:08:46 +01:00
2020-01-14 20:06:57 +01:00
2020-01-09 10:19:07 +01:00
2020-05-14 07:57:21 +02:00
2020-03-05 16:42:12 +01:00
2020-11-05 11:08:35 +01:00
2021-04-14 08:22:32 +02:00
2020-01-12 12:17:20 +01:00
2020-02-11 04:34:08 -08:00
2020-10-07 08:00:09 +02:00
2021-10-27 09:53:13 +02:00
2021-09-22 11:47:50 +02:00
2021-12-08 08:50:13 +01:00
2022-03-02 11:38:15 +01:00
2020-04-17 10:48:51 +02:00
2021-07-20 16:15:52 +02:00
2020-03-25 08:06:14 +01:00
2019-05-31 06:46:05 -07:00
2018-11-21 09:19:14 +01:00
2021-05-22 10:59:50 +02:00
2020-11-24 13:27:23 +01:00
2020-01-09 10:19:00 +01:00
2020-03-05 16:42:20 +01:00
2021-08-26 08:36:49 -04:00
2019-05-25 18:23:26 +02:00
2020-03-18 07:14:21 +01:00
2021-08-12 13:19:43 +02:00
2020-05-02 17:26:01 +02:00
2019-12-01 09:17:04 +01:00
2021-04-28 13:16:50 +02:00
2022-01-29 10:19:18 +01:00
2021-07-20 16:16:16 +02:00
2021-12-14 10:18:07 +01:00
2019-12-17 20:35:43 +01:00
2019-10-11 18:21:39 +02:00
2022-02-23 11:58:38 +01:00
2021-09-22 11:48:02 +02:00
2020-08-11 15:32:34 +02:00