From: Weiming Shi <bestswngs@gmail.com>
To: Carlos Maiolino <cem@kernel.org>
Cc: linux-xfs@vger.kernel.org, linux-kernel@vger.kernel.org,
Chandan Babu R <chandanrlinux@gmail.com>,
"Darrick J . Wong" <darrick.wong@oracle.com>,
Xiang Mei <xmei5@asu.edu>, Weiming Shi <bestswngs@gmail.com>,
co+af981e62f5c7171a@bugs.sh, stable@vger.kernel.org
Subject: [PATCH] xfs: validate buffer log item before reordering
Date: Sun, 13 Sep 2026 19:45:30 +0800 [thread overview]
Message-ID: <20260913114528.842015-3-bestswngs@gmail.com> (raw)
Log recovery reorders transaction items before buffer item pass1 validates
the format of region 0. A corrupt log can therefore supply a four-byte
region containing only blf_type and blf_size. xlog_recover_buf_reorder()
then reads blf_flags immediately past the allocation:
BUG: KASAN: slab-out-of-bounds in xlog_recover_buf_reorder
Read of size 2 at addr ffff88800e40e364 by task poc/133
Call Trace:
kasan_report mm/kasan/report.c:595
xlog_recover_buf_reorder fs/xfs/xfs_buf_item_recover.c:164
xlog_recover_reorder_trans fs/xfs/xfs_log_recover.c:1929
xlog_recover_commit_trans fs/xfs/xfs_log_recover.c:2053
xlog_recovery_process_trans fs/xfs/xfs_log_recover.c:2319
xlog_recover_process_data fs/xfs/xfs_log_recover.c:2510
xlog_do_recovery_pass fs/xfs/xfs_log_recover.c:3253
xlog_do_log_recovery fs/xfs/xfs_log_recover.c:3340
xlog_do_recover fs/xfs/xfs_log_recover.c:3377
xlog_recover fs/xfs/xfs_log_recover.c:3502
xfs_log_mount fs/xfs/xfs_log.c:617
xfs_mountfs fs/xfs/xfs_mount.c:1031
The buggy address is located 0 bytes to the right of
allocated 4-byte region [ffff88800e40e360, ffff88800e40e364)
Validate region 0 before inspecting the flags. Keep a malformed item on
the regular item list so that xlog_recover_buf_commit_pass1() reports the
corrupt log through the existing error path.
Fixes: 86ffa471d9ce ("xfs: refactor log recovery item sorting into a generic dispatch structure")
Reported-by: co+af981e62f5c7171a@bugs.sh
Closes: https://lore.kernel.org/all/aqZALi7GdVprcNOh@cronus.toxiclabs.cc/
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
---
fs/xfs/xfs_buf_item_recover.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/xfs/xfs_buf_item_recover.c b/fs/xfs/xfs_buf_item_recover.c
index 57929f115055..70e69ec731ac 100644
--- a/fs/xfs/xfs_buf_item_recover.c
+++ b/fs/xfs/xfs_buf_item_recover.c
@@ -161,6 +161,10 @@ xlog_recover_buf_reorder(
{
struct xfs_buf_log_format *buf_f = item->ri_buf[0].iov_base;
+ /* A short region 0 is rejected by xlog_recover_buf_commit_pass1. */
+ if (!xfs_buf_log_check_iovec(&item->ri_buf[0]))
+ return XLOG_REORDER_ITEM_LIST;
+
if (buf_f->blf_flags & XFS_BLF_CANCEL)
return XLOG_REORDER_CANCEL_LIST;
if (buf_f->blf_flags & XFS_BLF_INODE_BUF)
--
2.55.0
reply other threads:[~2026-09-13 11:48 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260913114528.842015-3-bestswngs@gmail.com \
--to=bestswngs@gmail.com \
--cc=cem@kernel.org \
--cc=chandanrlinux@gmail.com \
--cc=co+af981e62f5c7171a@bugs.sh \
--cc=darrick.wong@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=xmei5@asu.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®