Repository navigation
blk-mq: fix out-of-bounds read in blk_mq_free_rqs - #1283
blktests-ci-kpd[bot] wants to merge 1 commit into
Conversation
|
Upstream branch: 50d05c7 |
7efd8cd to
a0aeca9
Compare
|
Upstream branch: 5225b8e |
b825b3b to
933f964
Compare
a0aeca9 to
772381e
Compare
|
Upstream branch: 2f0c1cf |
933f964 to
a9c93ca
Compare
772381e to
0224dee
Compare
|
Upstream branch: 2f0c1cf |
a9c93ca to
0ebb93c
Compare
0224dee to
f14340f
Compare
|
Upstream branch: 5878583 |
0ebb93c to
c0f8db6
Compare
f14340f to
0e174bc
Compare
|
Upstream branch: 4982d35 |
c0f8db6 to
6510c44
Compare
0e174bc to
fbef20f
Compare
|
Upstream branch: 5dd1818 |
6510c44 to
9e81277
Compare
fbef20f to
4a650fc
Compare
|
Upstream branch: 6a5719c |
9e81277 to
3b0cfe2
Compare
9182022 to
7171e5a
Compare
372fcdc to
c6537fe
Compare
|
Upstream branch: 72d3fcf |
7171e5a to
0a1d7da
Compare
c6537fe to
eebb5bc
Compare
|
Upstream branch: 551c722 |
0a1d7da to
feba688
Compare
eebb5bc to
bbd3af0
Compare
|
Upstream branch: ce1e022 |
feba688 to
5bd65da
Compare
bbd3af0 to
a9c0b46
Compare
|
Upstream branch: e767a4e |
5bd65da to
0c0b777
Compare
a9c0b46 to
72d0f5e
Compare
|
Upstream branch: a74306e |
0c0b777 to
6deec4b
Compare
72d0f5e to
d980ad5
Compare
|
Upstream branch: None |
6deec4b to
9a34d97
Compare
d980ad5 to
83b99cc
Compare
|
Upstream branch: 22430ae |
9a34d97 to
fff1779
Compare
83b99cc to
9081535
Compare
|
Upstream branch: 69f80fe |
fff1779 to
25d18ae
Compare
9081535 to
6118c5c
Compare
A KASAN slab-out-of-bounds read can occur in blk_mq_free_rqs() when there is a mismatch between the number of hardware queues allocated for the IO scheduler (et->nr_hw_queues) and the number of hardware queues in the block tag set (set->nr_hw_queues). This mismatch can happen if blk_mq_update_nr_hw_queues() fails halfway through (e.g., due to memory pressure during blk_mq_prealloc_tag_set_tags()). In this error path, the elevator is restored with a larger number of hardware queues than the block tag set actually has. When the elevator is later freed, blk_mq_free_sched_tags() iterates up to the new et->nr_hw_queues and calls blk_mq_free_rqs(). In blk_mq_free_rqs(), it attempts to access set->tags[hctx_idx] to get the driver tags. Because set->nr_hw_queues was not updated due to the earlier failure, set->tags still has the old (smaller) size, leading to an out-of-bounds read. BUG: KASAN: slab-out-of-bounds in blk_mq_free_rqs+0xde/0x680 Read of size 8 at addr ffff88818d67fc28 by task syz-executor117/5839 Call Trace: blk_mq_free_rqs+0xde/0x680 blk_mq_free_map_and_rqs+0x40/0xf0 blk_mq_free_sched_tags blk_mq_free_sched_res+0xeb/0x280 elevator_change_done+0x1d2/0x5c0 elevator_change+0x34f/0x480 elv_iosched_store+0x504/0x630 queue_attr_store+0x207/0x2b0 To fix this, explicitly check if hctx_idx < set->nr_hw_queues before accessing set->tags[hctx_idx]. If hctx_idx >= set->nr_hw_queues, the hardware queue doesn't exist in the tag set, meaning there are no driver tags to clear mappings from. In this case, safely set drv_tags to NULL. The subsequent call to blk_mq_clear_rq_mapping() already handles a NULL drv_tags pointer and will safely return. This fix also prevents a similar out-of-bounds read in the failure path of blk_mq_alloc_rqs(), where a failure during new driver tag allocation could lead to blk_mq_free_rqs() being called with an hctx_idx greater than or equal to set->nr_hw_queues. Fixes: 04225d1 ("block: fix potential deadlock while running nr_hw_queue update") Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot Reported-by: syzbot+e90526cab23b9efcd03c@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=e90526cab23b9efcd03c Link: https://syzkaller.appspot.com/ai_job?id=827b5760-86a0-4f44-9c69-430b572eac12 Signed-off-by: Krystian Kaniewski <krystianmkaniewski@gmail.com> Reviewed-by: Nilay Shorff <nilay@linux.ibm.com>
|
Upstream branch: 7b63ef2 |
25d18ae to
61a71a6
Compare
Pull request for series with
subject: blk-mq: fix out-of-bounds read in blk_mq_free_rqs
version: 1
url: https://patchwork.kernel.org/series/1161970/