mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <Alexander.Levin@microsoft.com>
To: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"stable@vger.kernel.org" <stable@vger.kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>,
	Jens Axboe <axboe@kernel.dk>,
	Sasha Levin <Alexander.Levin@microsoft.com>
Subject: [PATCH AUTOSEL for 3.18 17/24] loop: fix concurrent lo_open/lo_release
Date: Sat, 3 Feb 2018 18:05:07 +0000	[thread overview]
Message-ID: <20180203180444.10801-17-alexander.levin@microsoft.com> (raw)
In-Reply-To: <20180203180444.10801-1-alexander.levin@microsoft.com>

From: Linus Torvalds <torvalds@linux-foundation.org>

[ Upstream commit ae6650163c66a7eff1acd6eb8b0f752dcfa8eba5 ]

范龙飞 reports that KASAN can report a use-after-free in __lock_acquire.
The reason is due to insufficient serialization in lo_release(), which
will continue to use the loop device even after it has decremented the
lo_refcnt to zero.

In the meantime, another process can come in, open the loop device
again as it is being shut down. Confusion ensues.

Reported-by: 范龙飞 <long7573@126.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
---
 drivers/block/loop.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/drivers/block/loop.c b/drivers/block/loop.c
index 6cb1beb47c25..94385b969f67 100644
--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -1512,9 +1512,8 @@ out:
 	return err;
 }
 
-static void lo_release(struct gendisk *disk, fmode_t mode)
+static void __lo_release(struct loop_device *lo)
 {
-	struct loop_device *lo = disk->private_data;
 	int err;
 
 	mutex_lock(&lo->lo_ctl_mutex);
@@ -1542,6 +1541,13 @@ out:
 	mutex_unlock(&lo->lo_ctl_mutex);
 }
 
+static void lo_release(struct gendisk *disk, fmode_t mode)
+{
+	mutex_lock(&loop_index_mutex);
+	__lo_release(disk->private_data);
+	mutex_unlock(&loop_index_mutex);
+}
+
 static const struct block_device_operations lo_fops = {
 	.owner =	THIS_MODULE,
 	.open =		lo_open,
-- 
2.11.0

  parent reply	other threads:[~2018-02-03 18:08 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-02-03 18:04 [PATCH AUTOSEL for 3.18 01/24] mtd: nand: gpmi: Fix failure when a erased page has a bitflip at BBM Sasha Levin
2018-02-03 18:04 ` [PATCH AUTOSEL for 3.18 03/24] mm,vmscan: Make unregister_shrinker() no-op if register_shrinker() failed Sasha Levin
2018-02-03 18:04 ` [PATCH AUTOSEL for 3.18 02/24] ipv6: icmp6: Allow icmp messages to be looped back Sasha Levin
2018-02-03 18:04 ` [PATCH AUTOSEL for 3.18 04/24] sget(): handle failures of register_shrinker() Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 05/24] spi: atmel: fixed spin_lock usage inside atmel_spi_remove Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 06/24] net: arc_emac: fix arc_emac_rx() error paths Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 07/24] scsi: storvsc: Fix scsi_cmd error assignments in storvsc_handle_error Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 08/24] tg3: Add workaround to restrict 5762 MRRS to 2048 Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 09/24] tg3: Enable PHY reset in MTU change path for 5720 Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 10/24] bnx2x: Improve reliability in case of nested PCI errors Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 11/24] led: core: Fix brightness setting when setting delay_off=0 Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 12/24] s390/dasd: fix wrongly assigned configuration data Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 13/24] xfs: quota: fix missed destroy of qi_tree_lock Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 14/24] xfs: quota: check result of register_shrinker() Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 16/24] drm/ttm: check the return value of kzalloc Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 15/24] e1000: fix disabling already-disabled warning Sasha Levin
2018-02-03 18:05 ` Sasha Levin [this message]
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 18/24] xen-netfront: enable device after manual module load Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 19/24] mdio-sun4i: Fix a memory leak Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 20/24] SolutionEngine771x: fix Ether platform data Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 21/24] xen/gntdev: Fix off-by-one error when unmapping with holes Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 22/24] xen/gntdev: Fix partial gntdev_mmap() cleanup Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 23/24] sctp: make use of pre-calculated len Sasha Levin
2018-02-03 18:05 ` [PATCH AUTOSEL for 3.18 24/24] net: gianfar_ptp: move set_fipers() to spinlock protecting area Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180203180444.10801-17-alexander.levin@microsoft.com \
    --to=alexander.levin@microsoft.com \
    --cc=axboe@kernel.dk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®