From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f175.google.com (mail-qk1-f175.google.com [209.85.222.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 11CB6418A36 for ; Fri, 31 Jul 2026 11:00:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.175 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785495617; cv=none; b=Mg5OSICSQ4cBJQWPOsD6VZ3C+lzJO7N/Q94eai2GzIb3wdqHiQjUbIca6GoXvwq5ATmBifTIvar/DBpklBCrlY9cYVhfJEJFPOGoj2yC8IvdrWSDDFGr7MMtopOCu8HNMT6a6ianf61Kfz2d68doRCT3qptheasrrZmKuvaU1Iw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785495617; c=relaxed/simple; bh=MPBCkx2e0hfZDwu6Ma3IcCnh1XLX7aXMhGljF2ciOho=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=R1kf8Kwsv73rW01ARsqZg6OiAl0gaArLgraDLbA17kiDcsVhFQVk18Q+YAQs9vY4MlgJhyCeBQm2CF+Mjs/dXTd+7o9Vw/w71T1kWZPCTfAYMuwHF/B1JTj38sJATi7HiGNlRf9+BSgr2oH5diIGDqtVx3oPYi3+iBTNL2D0Wsc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=VYig+NIU; arc=none smtp.client-ip=209.85.222.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="VYig+NIU" Received: by mail-qk1-f175.google.com with SMTP id af79cd13be357-930fad20240so40495285a.0 for ; Fri, 31 Jul 2026 04:00:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785495611; x=1786100411; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=E77D45gvvB/Gc6kYtlWwwpZQAm6W1TGjK8TmAiQ7i4U=; b=VYig+NIU6X8gYHtluXZvOkbXxo4O4tmvBdCefqrnzTm57JDzF/vyhyfDYoIXrD0F2Y N3HpHjeTw2wBAXuQjeiZa3OsJNLtAo+aa7MScWMNj0A/SQSs1twgyT+Uqp0pOZHPgDxu 3SUFchR+DL3G93xHsi0KzIcHLFqYp5Ie4hW/swv4Pik72GNfI5O5HUAzHtVW6Mus5JDj BoGFORIzDJHcnHhLUEJKEitHH4SbLZlp9PlBn/7ZiOvw3NiXNGFRHHpBlf5jrD6I6XRw iL/RdMxdxYbwXAZrkfCT7fKV+bBCmmvQyhWHHAfXQnL/KiSgniJRyTGuOUnJEOvCQueh ShSw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785495611; x=1786100411; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=E77D45gvvB/Gc6kYtlWwwpZQAm6W1TGjK8TmAiQ7i4U=; b=sIIfIUres3VCF2tWxtgDg9obVdpn759K7vQKIB38aZhfFI1lgpHQM+esV6Oh3lI2tj /dWgt51QfwExYYgVbbyAQHPhV9zHHaa9WyjTZ54NTkcsJaUMLjOxPsndv/715wvO57y1 6OZP53xBtVlp8I35ZHKiKV/N9c9Wiyrpi/btcl4WYoAqDsHY7tyfQT8vaFEafk2k3SGZ EUzdZItS+K7WtGxSRJD2dygGUcGCSGOyqf9Uq/b3cO07oR1Ng9W3FkFnhv9eusfZT7nX 78hZ4n7U2pLRKPRfR4xhkOKEIUtWysDvFFfTDko53Pz9omVYfF7mwrhdL1eSGknisHrp /AxQ== X-Forwarded-Encrypted: i=1; AHgh+Rpl7twu13nukmVTPC/jFv7JNHGcMpAY87P2JEO2G+8LKfiDfSIP8E5RBp2h2Vo09Tyk48NShSxxIDf3ip8=@vger.kernel.org X-Gm-Message-State: AOJu0YzEannnlAomDJbbBcJYgW5wDm1ymD5JutW0ma835fvWBEFMmjc6 OBQ/XXtbwDgszYvyK+K+eRNJISu2xoGWF6EK8A3WRRnHaCk+Y3pHdAzOySs1/6W/U2s= X-Gm-Gg: AR+sD10VRUBSElKpPSOxM+0n72iXKKPtbrjfi2nRM+tZezvoBdLzmc4TFUTvvJR2fOF z8/tDxeJojXiXONhh62mOuRTBccRq8lXkH+nrye/8MrD4U1fZjRU1CQAMoQk+81HchfmMxJmTbF DehgtITUXDz8arLLrRYCTOVeGzydvqBMSzzJa4eveOs/d34FsBXw8schtZLLVhNt4yXyGj6FHmf Y4ikGgqoRhLhyzqi5laipzA5y62f+2qR4ZzdVhtEINJq4+s87fMOHBBecCQ3qOHBpaQ49C4Jxqv 60BR7RQT60bf8gBRoQ8TaQ+JxMyqwWZ5QJoKqqFL5k5FlYtzm8CCaSbmmkzXZEHDvA9Ek2RfcE5 2jgrrH2U1yTuRRQ9k6CaFHlOzFoQHWJOqrjIAr/KOdHl5j/orSqbyykrSuRq73zSEC09kgFGgcU JQSGuESC9ByWOJXq+BhEVprpsSMB6PcLmHX/1KjFks+2dQI1M056WJzg5/ZI8JRxM/Xw== X-Received: by 2002:a05:620a:711a:b0:92e:46e5:8f12 with SMTP id af79cd13be357-934967bdf8emr178039385a.30.1785495611077; Fri, 31 Jul 2026 04:00:11 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-908435b58e0sm7686826d6.31.2026.07.31.04.00.10 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 04:00:10 -0700 (PDT) From: David Lee To: shaggy@kernel.org Cc: David Lee , Kyle Zeng , Dominik 'Disconnect3d' Czarnota , jfs-discussion@lists.sourceforge.net, linux-kernel@vger.kernel.org Subject: [PATCH] jfs: pin metapage during synchronous writeback Date: Fri, 31 Jul 2026 11:00:06 +0000 Message-ID: <20260731110008.543282-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit release_metapage() decrements mp->count from one to zero but keeps the struct metapage pointer in its local variable mp. For synchronous writeback, release_metapage() calls metapage_write_one(), which in turn calls metapage_write_folio(). metapage_write_folio() clears META_dirty, submits the I/O, and this unlocks the folio while synchronous I/O is in progress. After writeback completes, kswapd can acquire the folio lock before release_metapage(). metapage_release_folio() then sees mp->count == 0 and META_dirty clear, removes mp from the folio, and frees the struct metapage. release_metapage() subsequently reacquires the folio lock and passes its now-dangling mp pointer to drop_metapage(), which does an use-after-free read of mp->count. Increment mp->count before calling metapage_write_one(), and decrement it only after release_metapage() has reacquired the folio lock. The nonzero count makes metapage_release_folio() leave the struct metapage allocated throughout the unlocked writeback interval. Once release_metapage() holds the folio lock again, it can drop the temporary reference and safely finish using mp. Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. Assisted-by: Codex:gpt-5.6-sol gpt-5.5-cyber Signed-off-by: Kyle Zeng --- Trail of Bits has a reproducer for this bug that triggers a KASAN use-after-free and can share if needed. fs/jfs/jfs_metapage.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/fs/jfs/jfs_metapage.c b/fs/jfs/jfs_metapage.c index 41fe12e641ce..d1962a44125a 100644 --- a/fs/jfs/jfs_metapage.c +++ b/fs/jfs/jfs_metapage.c @@ -882,9 +882,12 @@ void release_metapage(struct metapage * mp) folio_mark_dirty(folio); if (test_bit(META_sync, &mp->flag)) { clear_bit(META_sync, &mp->flag); + /* Pin mp while metapage_write_one() drops the folio lock. */ + mp->count++; if (metapage_write_one(folio)) jfs_error(mp->sb, "metapage_write_one() failed\n"); folio_lock(folio); + mp->count--; } } else if (mp->lsn) /* discard_metapage doesn't remove it */ remove_from_logsync(mp); -- 2.53.0