From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 965A9331EA5 for ; Thu, 30 Jul 2026 03:21:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785381680; cv=none; b=uLS46STQZ/3Pn6bDKFHiwl/6puOPKLo/c4BPHcJ3uTAvCBqS21WUTRhtZuH88d02L9ILrue7fe/aCMbMC10vZMeApBgKv2p6m7wj/ZGUglYcU0dbd/UGzp7Ixzd+2wcxThSCfyK64YK5jjjU9amv1gUGsxtACloSj2H55Rn2qsI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785381680; c=relaxed/simple; bh=t2huo+mCGdLek46QfERmroLw4DKaWEsCEWpbUxuoh7E=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=DJq7cocdItCYp85hgtztB/1iYRiMG3f54CjGXh5ENZCJrMV1bpToJE/xBR5rjIelGKnIkxd4BF9vDKOjpWjM94u8FwH3aiQfHkxv+0wc/B9imECVM/Eprm5d9Tqf3uSvOPNB6J26xrhyA7cuiMXhVWHHPfEikjOeK7Dt3y9fduE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=COjsOfxq; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="COjsOfxq" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-38dc4553f62so1627450a91.0 for ; Wed, 29 Jul 2026 20:21:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785381678; x=1785986478; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=dRRJUQ6lF/VrBQ+d8mUK6cjq2Ts7AEbYsxt8dcHAa3Q=; b=COjsOfxqTuKbb5cOVVTEgmBhwdsO8uThvaNp8vDyxqvnk0PMeJjJlzA8bfw4E8uyUX 6FV23zl5h9x40FBq13uWnRVY8/nX+REpMdChNoKLxLZ54gbSokUqRVJA/+yNwtDFIpUX Hg9psvWJZnj41p8YZNzEJUdj6UTaEynOwHBssqzhIQxH6bymzlPgxSRTCRZXrdMDRmhC loIq1j9oRDsOUTWi8NDfQ5XiChUuzbvhkwimt758iOEweE3CXaV3RJwvUoFf+di7kAsX VwBZhh40zJDWBjKFb2OSCAHdefsIJKOHMTMqulAPp0HtKM6ikA5UaHB84HJY0E41CkYW GJZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785381678; x=1785986478; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dRRJUQ6lF/VrBQ+d8mUK6cjq2Ts7AEbYsxt8dcHAa3Q=; b=nEhzBzYNFIwX6EJ/wsYogSyO0XzFH5f1FOepG/WsPRMQ6Jw5YUmpa747c7FmekgAvP JNHGddJC3QnrG95xn/Mt3PAOBW9DN+1fOa7TCEK/eyhz7aRU8gWyqdKc0Dn6SOY1A6aQ MpKVA+M5sBPBxHw4SXQVV97BGW18dAipv36HXSUoAJq9qdur+q83gzgO/M2MTA9+5ykQ y+v8nEw3SGUQINVpFtKUeBzpMQI34A0RKuMc+BRcigimNQQbDQifGoR1Ha+YTNRzz70H 1VSwEs4HZqNkyKP0/5bwrerWJX9b5+37GRRDD6o4rh6IvM0OvXZK8VaKWva4FbekgY4h RvaQ== X-Forwarded-Encrypted: i=1; AHgh+Rr93mI6OA5GQqoCUcUBI6qiaY7wGz2k8Wp+ALcbMwbyG5Mez1IScUigqrhqi7DQRbiRLoyHKrvLLaFEIKU=@vger.kernel.org X-Gm-Message-State: AOJu0Yz3ZodVJoTq5Ru3rc9lrok0jCC2jMZI6wTQpdJaAGynmp0b34nJ jdD5iHksBHPBUcTDIy8FOfh8D2tnMkHsW6Pcpta5/MjxPZMXvTbryI3R X-Gm-Gg: AR+sD12hfOCiyVtkDsXgOUZoHWwgqLmWh7/bAkkGyXivI7/MYxylcbQaMDoVrcyG304 D2ix9UKbbbt0f+NEXO74ozxNbuMcHZ6kHjLFPAOL+yxp+KbI5n7b9wz3mOK8F6BacuYCllUFErU YRSzcUAKXBvPX/oK3Rict+rBRB/N4nSuzkO8mNSnjWe+2mvJlj3g6pTtGQEgzj6h0KzxTAIPUH6 QTTM9zMUd4/lCs9Uer3YZZuUSdFB1H8mIHGfa6v93E5JqkwXlEl7MPVPlgciUoPBggG9pCfKUax OlHJk0lQhRP6CdHu3YClYGU0SnyGeoItTvqejrvZqPQPTo67QoTFtYtcAdkpabZ8h7c33bBM/6g hIdVvPGLgKcbJBVUzjNtgawYuzpzx7CQx1sCsESggRn4S2rZ4hUazt+Fe2V1GXivv0jqU1hG6O0 uYYzbyLEcZdV0GpPuNxgqIOHC3N85sHRkkoLxlt7ZHAbcBg029KGAhLWEbeO49iHJf0A== X-Received: by 2002:a17:90b:1d8c:b0:38e:8300:af51 with SMTP id 98e67ed59e1d1-38f9bd62f1dmr780987a91.8.1785381677731; Wed, 29 Jul 2026 20:21:17 -0700 (PDT) Received: from Default ([2409:40f4:1008:1710:a945:87ad:2d3e:163d]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13e72643a12sm22869726c88.5.2026.07.29.20.21.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 29 Jul 2026 20:21:16 -0700 (PDT) From: Jeffin Philip To: a.hindborg@kernel.org Cc: leitao@debian.org, viro@zeniv.linux.org.uk, sage@newdream.net, linux-kernel@vger.kernel.org, syzbot , syzbot+8358d1f3d9c15bdf1c9a@syzkaller.appspotmail.com, Jeffin Philip Subject: [PATCH] configfs: fix race between symlink and rmdir Date: Thu, 30 Jul 2026 08:50:40 +0530 Message-ID: <20260730032040.95378-1-jeffinphilip14@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: syzbot A race condition between configfs_rmdir() and configfs_symlink() can lead to a use-after-free of a config_item. When a directory is removed, configfs_rmdir() frees the associated config_item but leaves the dentry hashed until vfs_rmdir() calls d_delete(). This creates a window where a concurrent symlinkat() can find the hashed dentry, see that !d_unhashed(dentry) is true, and attempt to increment the refcount of the already freed config_item, triggering a warning: refcount_t: addition on 0; use-after-free. WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 ... Call Trace: __refcount_add include/linux/refcount.h:-1 [inline] __refcount_inc include/linux/refcount.h:366 [inline] refcount_inc include/linux/refcount.h:383 [inline] kref_get include/linux/kref.h:45 [inline] config_item_get+0x88/0x90 fs/configfs/item.c:104 configfs_get_config_item fs/configfs/configfs_internal.h:127 [inline] get_target fs/configfs/symlink.c:128 [inline] configfs_symlink+0x4ab/0x1030 fs/configfs/symlink.c:185 vfs_symlink+0x18b/0x330 fs/namei.c:5660 filename_symlinkat+0x1cd/0x420 fs/namei.c:5685 __do_sys_symlinkat fs/namei.c:5705 [inline] __se_sys_symlinkat+0x4e/0x2b0 fs/namei.c:5700 To fix this, add d_drop(dentry) in configfs_rmdir() immediately after detaching the group/item and before unlinking the object. This ensures that any concurrent kern_path() will either not find the dentry, or configfs_get_config_item() will see d_unhashed(dentry) == true and safely return NULL. However, adding d_drop(dentry) exposes a secondary use-after-free bug in create_link(). configfs_symlink() calls get_target(), which resolves the path, gets the config_item, and then immediately drops the path reference. If configfs_rmdir() runs concurrently, it drops its config_item reference, and vfs_rmdir() calls d_delete_notify(). Since the dentry has only 1 reference left, dentry_unlink_inode() is called, freeing the configfs_dirent. Later, create_link() accesses the freed configfs_dirent. To fix this secondary issue, modify get_target() to return the path, and hold the path reference in configfs_symlink() until after create_link() finishes. By holding the path reference, the dentry's refcount remains >= 2, preventing d_delete() from calling dentry_unlink_inode(), which keeps the configfs_dirent alive. The path is safely cleaned up using the __free(path_put) attribute in configfs_symlink(). Fixes: 98702467f829 ("configfs: remove unnecessary dentry_unhash on rmdir, dir rename") Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot Reported-by: syzbot+8358d1f3d9c15bdf1c9a@syzkaller.appspotmail.com Tested-by: Jeffin Philip Reviewed-by: Jeffin Philip Signed-off-by: Jeffin Philip Closes: https://syzkaller.appspot.com/bug?extid=8358d1f3d9c15bdf1c9a Link: https://syzkaller.appspot.com/ai_job?id=13fec684-23f7-4f06-99db-ed37ae92a405 Cc: Breno Leitao --- fs/configfs/dir.c | 2 ++ fs/configfs/symlink.c | 14 +++++++------- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/fs/configfs/dir.c b/fs/configfs/dir.c index 3c88f13f1ca2..b0812432f6c5 100644 --- a/fs/configfs/dir.c +++ b/fs/configfs/dir.c @@ -1552,12 +1552,14 @@ static int configfs_rmdir(struct inode *dir, struct dentry *dentry) if (sd->s_type & CONFIGFS_USET_DIR) { configfs_detach_group(dentry); + d_drop(dentry); mutex_lock(&subsys->su_mutex); client_disconnect_notify(parent_item, item); unlink_group(to_config_group(item)); } else { configfs_detach_item(dentry); + d_drop(dentry); mutex_lock(&subsys->su_mutex); client_disconnect_notify(parent_item, item); diff --git a/fs/configfs/symlink.c b/fs/configfs/symlink.c index 31eb28b27309..c8a2d9ad6cac 100644 --- a/fs/configfs/symlink.c +++ b/fs/configfs/symlink.c @@ -114,18 +114,17 @@ static int create_link(struct config_item *parent_item, } -static int get_target(const char *symname, struct config_item **target, - struct super_block *sb) +static int get_target(const char *symname, struct path *path, + struct config_item **target, struct super_block *sb) { - struct path path __free(path_put) = {}; int ret; - ret = kern_path(symname, LOOKUP_FOLLOW|LOOKUP_DIRECTORY, &path); + ret = kern_path(symname, LOOKUP_FOLLOW | LOOKUP_DIRECTORY, path); if (ret) return ret; - if (path.dentry->d_sb != sb) + if (path->dentry->d_sb != sb) return -EPERM; - *target = configfs_get_config_item(path.dentry); + *target = configfs_get_config_item(path->dentry); if (!*target) return -ENOENT; return 0; @@ -136,6 +135,7 @@ int configfs_symlink(struct mnt_idmap *idmap, struct inode *dir, struct dentry *dentry, const char *symname) { int ret; + struct path path __free(path_put) = {}; struct configfs_dirent *sd; struct config_item *parent_item; struct config_item *target_item = NULL; @@ -182,7 +182,7 @@ int configfs_symlink(struct mnt_idmap *idmap, struct inode *dir, * AV, a thoroughly annoyed bastard. */ inode_unlock(dir); - ret = get_target(symname, &target_item, dentry->d_sb); + ret = get_target(symname, &path, &target_item, dentry->d_sb); inode_lock(dir); if (ret) goto out_put; -- 2.55.0