From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from szxga04-in.huawei.com (szxga04-in.huawei.com [45.249.212.190]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F0DC84400 for ; Tue, 23 Jan 2024 04:55:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=45.249.212.190 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1705985726; cv=none; b=U5nZ6xH/x6kIHQ8MeEGr+zZlRil1paktv98ClICxx09vNEDlNweS6WeiAlCYLc1mTktrIKcfuqO0dRFLUKmlK1KVP8qDi6IQa0utF/pK9j2txSiYkiSnpOowH7smAx96Qv6c5/wZwgj+KpNGXYQgarL9EOyDqjhg2MQFnRN7sAw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1705985726; c=relaxed/simple; bh=rAgcmrG0t3aSDcPvl2Ic++oT+SicOQH1vWkViIaa/mM=; h=Subject:To:CC:References:From:Message-ID:Date:MIME-Version: In-Reply-To:Content-Type; b=B1l7jWE5TeoQL7PzxqJNcCA1X1XaJq6gfDzKfuTIZAS753ssZmN+RA5A5hrRQCX1pmrsLu8e6R7ZHwi7Pmx0y9FWLSEAiMy8GA3ofleGiKO4aU1XvDP8DCUs1Fh22yJe6SOCXQ/hjSXYI60QPN1yuc7TzeGmnbC4jKfS0D+uKCs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; arc=none smtp.client-ip=45.249.212.190 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Received: from mail.maildlp.com (unknown [172.19.163.17]) by szxga04-in.huawei.com (SkyGuard) with ESMTP id 4TJvrj71Z6z1xmWc; Tue, 23 Jan 2024 12:54:29 +0800 (CST) Received: from kwepemm600013.china.huawei.com (unknown [7.193.23.68]) by mail.maildlp.com (Postfix) with ESMTPS id 15BB71A0172; Tue, 23 Jan 2024 12:55:21 +0800 (CST) Received: from [10.174.178.46] (10.174.178.46) by kwepemm600013.china.huawei.com (7.193.23.68) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.35; Tue, 23 Jan 2024 12:55:20 +0800 Subject: Re: [Linux Kernel Bug] memory leak in ubi_attach To: Chenyuan Yang , , , , CC: , , Zijie Zhao References: From: Zhihao Cheng Message-ID: <10779b09-3413-6374-b4a1-1efd8821c5f2@huawei.com> Date: Tue, 23 Jan 2024 12:55:19 +0800 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:68.0) Gecko/20100101 Thunderbird/68.5.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset="utf-8"; format=flowed Content-Transfer-Encoding: 8bit X-ClientProxiedBy: dggems706-chm.china.huawei.com (10.3.19.183) To kwepemm600013.china.huawei.com (7.193.23.68) 在 2024/1/23 11:53, Chenyuan Yang 写道: > Dear Linux Kernel Developers for UBI, > > We encountered "memory leak in ubi_attach" when testing UBI with > Syzkaller and our generated specifications. > > syz repro: https://drive.google.com/file/d/17FoGw6akfufz05U-oRBP2wXmOiFF1VUq/view?usp=drive_link > C reproducer: https://drive.google.com/file/d/1ayd3lmHPvqNoI01pQEdU832EktpTUnZ_/view?usp=drive_link > report: https://drive.google.com/file/d/1hC2arY3FbQt-6L5rbDfY-DQ2oH82IIGq/view?usp=drive_link > stats: https://drive.google.com/file/d/1REig9fV0H1fYPWaiicc-JVLlCpo7TTw4/view?usp=drive_link I can't open above links in company, may you post these files in attachment? > > This memory leak is triggered by `ioctl$UBI_IOCATT`, where > `ubi_attach_info` invokes `kmem_cache_create` > (https://elixir.bootlin.com/linux/v6.7/source/drivers/mtd/ubi/attach.c#L1464). > It seems that the memory leak occurs when the slab cache is > successfully created. I apologize for not being able to conduct a > deeper analysis of the root cause, as my expertise in UBI drivers is > limited. > > If you have any questions or require more information, please feel > free to contact us. > > Reported-by: Chenyuan Yang > > Best, > Chenyuan > > > ______________________________________________________ > Linux MTD discussion mailing list > http://lists.infradead.org/mailman/listinfo/linux-mtd/ >