Baokun Li
f9c1f24860
ext4: fix null-ptr-deref in ext4_write_info
...
I caught a null-ptr-deref bug as follows:
==================================================================
KASAN: null-ptr-deref in range [0x0000000000000068-0x000000000000006f]
CPU: 1 PID: 1589 Comm: umount Not tainted 5.10.0-02219-dirty #339
RIP: 0010:ext4_write_info+0x53/0x1b0
[...]
Call Trace:
dquot_writeback_dquots+0x341/0x9a0
ext4_sync_fs+0x19e/0x800
__sync_filesystem+0x83/0x100
sync_filesystem+0x89/0xf0
generic_shutdown_super+0x79/0x3e0
kill_block_super+0xa1/0x110
deactivate_locked_super+0xac/0x130
deactivate_super+0xb6/0xd0
cleanup_mnt+0x289/0x400
__cleanup_mnt+0x16/0x20
task_work_run+0x11c/0x1c0
exit_to_user_mode_prepare+0x203/0x210
syscall_exit_to_user_mode+0x5b/0x3a0
do_syscall_64+0x59/0x70
entry_SYSCALL_64_after_hwframe+0x44/0xa9
==================================================================
Above issue may happen as follows:
-------------------------------------
exit_to_user_mode_prepare
task_work_run
__cleanup_mnt
cleanup_mnt
deactivate_super
deactivate_locked_super
kill_block_super
generic_shutdown_super
shrink_dcache_for_umount
dentry = sb->s_root
sb->s_root = NULL <--- Here set NULL
sync_filesystem
__sync_filesystem
sb->s_op->sync_fs > ext4_sync_fs
dquot_writeback_dquots
sb->dq_op->write_info > ext4_write_info
ext4_journal_start(d_inode(sb->s_root), EXT4_HT_QUOTA, 2)
d_inode(sb->s_root)
s_root->d_inode <--- Null pointer dereference
To solve this problem, we use ext4_journal_start_sb directly
to avoid s_root being used.
Cc: stable@kernel.org
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20220805123947.565152-1-libaokun1@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
2022-09-29 10:39:04 -04:00
..
2022-07-02 18:52:21 +09:00
2022-05-09 16:21:44 -04:00
2022-08-01 19:53:31 +02:00
2022-08-13 17:20:51 -07:00
2022-07-17 17:31:42 -07:00
2022-08-02 12:34:03 -04:00
2022-05-09 16:21:44 -04:00
2022-08-28 10:44:04 -07:00
2022-08-31 16:41:10 +01:00
2022-08-11 12:41:07 -07:00
2022-08-30 20:08:13 -05:00
2022-08-02 12:34:03 -04:00
2022-02-22 18:30:28 +01:00
2022-08-02 12:34:02 -04:00
2022-08-11 12:41:07 -07:00
2022-02-25 11:56:13 +01:00
2022-01-24 14:17:02 +01:00
2022-08-01 09:31:46 -05:00
2022-05-09 16:21:45 -04:00
2022-06-24 20:40:19 +02:00
2022-05-09 16:21:45 -04:00
2022-08-05 16:32:45 -07:00
2022-08-01 10:14:07 +09:00
2022-04-28 16:31:10 +02:00
2022-08-05 16:32:45 -07:00
2022-09-29 10:39:04 -04:00
2022-08-08 11:18:31 -07:00
2022-08-07 10:03:24 -07:00
2022-08-02 12:34:03 -04:00
2022-08-09 14:13:59 +01:00
2022-08-08 20:04:35 -07:00
2022-08-11 13:11:49 -07:00
2022-06-29 08:51:06 -04:00
2022-08-03 10:35:43 -07:00
2022-08-02 12:34:02 -04:00
2022-05-09 16:21:45 -04:00
2022-08-08 20:04:35 -07:00
2022-08-11 13:11:49 -07:00
2022-07-14 12:14:32 -06:00
2022-08-05 16:32:45 -07:00
2022-06-03 14:42:24 -07:00
2022-08-03 10:35:43 -07:00
2022-07-28 10:57:25 +02:00
2022-08-15 21:07:01 -05:00
2022-08-04 10:28:48 -04:00
2022-05-09 16:21:44 -04:00
2022-07-14 10:10:12 +02:00
2022-08-22 11:40:01 -07:00
2022-08-09 14:56:49 -07:00
2022-08-03 10:35:43 -07:00
2022-07-26 13:38:47 +02:00
2022-08-03 10:35:43 -07:00
2022-08-22 11:33:02 -07:00
2022-08-28 14:02:45 -07:00
2022-05-09 16:21:44 -04:00
2022-03-22 15:57:03 -07:00
2022-06-29 08:51:07 -04:00
2022-08-17 11:23:31 +02:00
2022-08-20 15:17:45 -07:00
2022-08-03 14:38:02 -07:00
2022-05-09 16:21:44 -04:00
2022-05-09 16:21:44 -04:00
2022-08-05 16:32:45 -07:00
2022-08-03 10:35:43 -07:00
2022-05-09 16:21:46 -04:00
2022-05-23 20:24:12 -05:00
2022-08-28 14:02:45 -07:00
2022-04-05 15:39:19 +02:00
2022-05-27 11:22:03 -07:00
2022-06-17 19:01:28 -04:00
2022-08-05 16:32:45 -07:00
2022-07-14 12:14:32 -06:00
2022-08-03 10:35:43 -07:00
2022-02-14 10:37:32 +09:00
2022-05-09 16:21:46 -04:00
2022-07-15 23:42:30 -07:00
2022-08-13 13:50:11 -07:00
2022-08-11 13:11:49 -07:00
2022-08-03 13:50:22 -07:00
2022-08-08 10:39:29 -07:00
2022-03-08 12:55:29 -06:00
2022-03-03 20:38:56 -08:00
2022-04-15 14:49:56 -07:00
2022-04-22 10:57:18 -07:00
2022-02-09 09:50:02 -08:00
2022-08-03 10:35:43 -07:00
2022-03-03 20:38:56 -08:00
2022-07-16 09:19:15 -04:00
2022-08-05 16:32:45 -07:00
2022-08-17 14:33:03 -07:00
2022-08-08 22:37:22 -04:00
2022-07-17 17:31:40 -07:00
2022-08-19 14:02:24 -07:00
2022-06-10 16:10:23 -04:00
2022-08-03 13:50:22 -07:00
2022-06-05 15:03:03 -04:00
2022-01-18 09:23:19 +02:00
2021-12-09 14:09:36 -05:00
2022-08-28 14:02:43 -07:00
2022-05-19 23:25:10 -04:00
2022-08-18 09:39:33 +02:00
2022-06-04 19:00:05 -07:00
2022-04-01 19:35:56 -07:00
2022-08-08 18:06:42 -07:00
2022-05-30 10:56:18 -07:00
2022-06-16 19:58:21 -07:00
2022-05-09 16:21:44 -04:00
2022-08-17 15:08:58 -04:00
2022-07-24 18:39:10 -06:00
2022-08-05 16:32:45 -07:00
2022-07-05 16:18:21 -04:00
2022-08-03 10:35:43 -07:00
2022-08-09 09:52:28 -07:00
2022-08-17 11:27:11 +02:00
2022-08-03 13:50:22 -07:00
2022-05-27 11:22:03 -07:00
2022-08-17 11:23:31 +02:00
2022-06-28 13:58:05 -04:00
2022-08-08 22:37:15 -04:00
2022-08-05 16:32:45 -07:00
2022-01-11 09:03:05 -08:00
2022-05-22 21:03:01 +01:00
2022-01-17 05:49:30 +02:00
2022-08-08 22:37:23 -04:00
2022-05-31 14:10:54 -07:00
2022-08-08 11:10:02 -07:00
2022-04-26 13:36:25 -07:00
2022-01-22 08:33:36 +02:00
2022-08-20 15:17:45 -07:00
2022-07-15 22:08:59 +02:00