mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store
@ 2026-09-14 16:38 syzbot
  2026-09-15 11:00 ` Edward Adam Davis
                   ` (2 more replies)
  0 siblings, 3 replies; 13+ messages in thread
From: syzbot @ 2026-09-14 16:38 UTC (permalink / raw)
  To: dakr, driver-core, gregkh, linux-kernel, rafael, syzkaller-bugs

Hello,

syzbot found the following issue on:

HEAD commit:    50d05c7c76c9 Merge tag 'landlock-7.3-rc3' of git://git.ker..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15489c8e580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=85bc5cc2fc7394d9
dashboard link: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
userspace arch: i386
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=17de9905580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=11f042d1580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-50d05c7c.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/303a0ade8f9e/vmlinux-50d05c7c.xz
kernel image: https://storage.googleapis.com/syzbot-assets/70b8ca71442b/bzImage-50d05c7c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com

==================================================================
BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917

CPU: 2 UID: 0 PID: 5917 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
 print_address_description mm/kasan/report.c:378 [inline]
 print_report+0x13d/0x4b0 mm/kasan/report.c:482
 kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
 kobject_action_type lib/kobject_uevent.c:86 [inline]
 kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
 bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
 bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
 sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
 kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x6af/0x1050 fs/read_write.c:687
 ksys_write+0x12a/0x250 fs/read_write.c:739
 do_syscall_32_irqs_on arch/x86/entry/syscall_32.c:79 [inline]
 __do_fast_syscall_32+0x13a/0x8b0 arch/x86/entry/syscall_32.c:291
 do_fast_syscall_32+0x32/0x70 arch/x86/entry/syscall_32.c:316
 entry_SYSENTER_compat_after_hwframe+0x84/0x8e
RIP: 0023:0xf702efec
Code: Unable to access opcode bytes at 0xf702efc2.
RSP: 002b:00000000ffa3eb5c EFLAGS: 00000296 ORIG_RAX: 0000000000000004
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000080000280
RDX: 000000000000ff0a RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
 </TASK>

The buggy address belongs to the variable:
 kobject_actions+0xdff/0x4e80

The buggy address belongs to the physical page:
page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xd725
flags: 0xfff00000002000(reserved|node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000002000 ffffea000035c948 ffffea000035c948 0000000000000000
raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner info is not present (never set?)

Memory state around the buggy address:
 ffffffff8d725480: f9 f9 f9 f9 00 06 f9 f9 f9 f9 f9 f9 00 06 f9 f9
 ffffffff8d725500: f9 f9 f9 f9 00 00 01 f9 f9 f9 f9 f9 00 00 02 f9
>ffffffff8d725580: f9 f9 f9 f9 00 06 f9 f9 f9 f9 f9 f9 00 07 f9 f9
                            ^
 ffffffff8d725600: f9 f9 f9 f9 00 00 06 f9 f9 f9 f9 f9 00 04 f9 f9
 ffffffff8d725680: f9 f9 f9 f9 00 06 f9 f9 f9 f9 f9 f9 00 05 f9 f9
==================================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store
  2026-09-14 16:38 [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store syzbot
@ 2026-09-15 11:00 ` Edward Adam Davis
  2026-09-15 11:22   ` syzbot
  2026-09-15 11:24 ` Edward Adam Davis
  2026-09-15 12:20 ` [PATCH] sysfs: prevent writing excessively large files Edward Adam Davis
  2 siblings, 1 reply; 13+ messages in thread
From: Edward Adam Davis @ 2026-09-15 11:00 UTC (permalink / raw)
  To: syzbot+9a321aea9d851b299486; +Cc: linux-kernel, syzkaller-bugs

From: Edward Aadm Davis <eadavis@sina.com>

#syz test: upstream 50d05c7c76c9

diff --git a/lib/kobject_uevent.c b/lib/kobject_uevent.c
index ddbc4d7482d2..25c89a36fb39 100644
--- a/lib/kobject_uevent.c
+++ b/lib/kobject_uevent.c
@@ -83,7 +83,8 @@ static int kobject_action_type(const char *buf, size_t count,
 	for (action = 0; action < ARRAY_SIZE(kobject_actions); action++) {
 		if (strncmp(kobject_actions[action], buf, count_first) != 0)
 			continue;
-		if (kobject_actions[action][count_first] != '\0')
+		if (count_first <= strlen(kobject_actions[action]) &&
+		    kobject_actions[action][count_first] != '\0')
 			continue;
 		if (args)
 			*args = args_start;

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store
  2026-09-15 11:00 ` Edward Adam Davis
@ 2026-09-15 11:22   ` syzbot
  0 siblings, 0 replies; 13+ messages in thread
From: syzbot @ 2026-09-15 11:22 UTC (permalink / raw)
  To: eadavis, linux-kernel, syzkaller-bugs

Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
Tested-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com

Tested on:

commit:         50d05c7c Merge tag 'landlock-7.3-rc3' of git://git.ker..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=1030fdf9580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=85bc5cc2fc7394d9
dashboard link: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
userspace arch: i386
patch:          https://syzkaller.appspot.com/x/patch.diff?x=13c07905580000

Note: testing is done by a robot and is best-effort only.

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store
  2026-09-14 16:38 [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store syzbot
  2026-09-15 11:00 ` Edward Adam Davis
@ 2026-09-15 11:24 ` Edward Adam Davis
  2026-09-15 12:06   ` syzbot
  2026-09-15 12:20 ` [PATCH] sysfs: prevent writing excessively large files Edward Adam Davis
  2 siblings, 1 reply; 13+ messages in thread
From: Edward Adam Davis @ 2026-09-15 11:24 UTC (permalink / raw)
  To: syzbot+9a321aea9d851b299486; +Cc: linux-kernel, syzkaller-bugs

From: Edward Aadm Davis <eadavis@sina.com>

#syz test: upstream 50d05c7c76c9

diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
index cd5bb0f9fee6..a63130d18680 100644
--- a/fs/sysfs/file.c
+++ b/fs/sysfs/file.c
@@ -228,10 +228,12 @@ static const struct kernfs_ops sysfs_file_kfops_ro = {
 };
 
 static const struct kernfs_ops sysfs_file_kfops_wo = {
+	.atomic_write_len	= PAGE_SIZE,
 	.write		= sysfs_kf_write,
 };
 
 static const struct kernfs_ops sysfs_file_kfops_rw = {
+	.atomic_write_len	= PAGE_SIZE,
 	.seq_show	= sysfs_kf_seq_show,
 	.write		= sysfs_kf_write,
 };

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store
  2026-09-15 11:24 ` Edward Adam Davis
@ 2026-09-15 12:06   ` syzbot
  0 siblings, 0 replies; 13+ messages in thread
From: syzbot @ 2026-09-15 12:06 UTC (permalink / raw)
  To: eadavis, linux-kernel, syzkaller-bugs

Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
Tested-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com

Tested on:

commit:         50d05c7c Merge tag 'landlock-7.3-rc3' of git://git.ker..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=14307905580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=85bc5cc2fc7394d9
dashboard link: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
userspace arch: i386
patch:          https://syzkaller.appspot.com/x/patch.diff?x=147348c9580000

Note: testing is done by a robot and is best-effort only.

^ permalink raw reply	[flat|nested] 13+ messages in thread

* [PATCH] sysfs: prevent writing excessively large files
  2026-09-14 16:38 [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store syzbot
  2026-09-15 11:00 ` Edward Adam Davis
  2026-09-15 11:24 ` Edward Adam Davis
@ 2026-09-15 12:20 ` Edward Adam Davis
  2026-09-16  7:17   ` Greg KH
  2026-09-17  7:34   ` Greg KH
  2 siblings, 2 replies; 13+ messages in thread
From: Edward Adam Davis @ 2026-09-15 12:20 UTC (permalink / raw)
  To: syzbot+9a321aea9d851b299486
  Cc: dakr, driver-core, gregkh, linux-kernel, rafael, syzkaller-bugs

Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
file write via sysfs_kf_write() may result in an out-of-bounds read when
checking for the null terminator of a string element in the kobject_actions
array within kobject_action_type(), potentially hitting:

BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
Call Trace:
 kobject_action_type lib/kobject_uevent.c:86 [inline]
 kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
 bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
 bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
 sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
 kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x6af/0x1050 fs/read_write.c:687

Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
properly.

Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
Reported-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
Tested-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
Signed-off-by: Edward Adam Davis <eadavis@sina.com>
---
 fs/sysfs/file.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
index cd5bb0f9fee6..a63130d18680 100644
--- a/fs/sysfs/file.c
+++ b/fs/sysfs/file.c
@@ -228,10 +228,12 @@ static const struct kernfs_ops sysfs_file_kfops_ro = {
 };
 
 static const struct kernfs_ops sysfs_file_kfops_wo = {
+	.atomic_write_len	= PAGE_SIZE,
 	.write		= sysfs_kf_write,
 };
 
 static const struct kernfs_ops sysfs_file_kfops_rw = {
+	.atomic_write_len	= PAGE_SIZE,
 	.seq_show	= sysfs_kf_seq_show,
 	.write		= sysfs_kf_write,
 };
-- 
2.43.0


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [PATCH] sysfs: prevent writing excessively large files
  2026-09-15 12:20 ` [PATCH] sysfs: prevent writing excessively large files Edward Adam Davis
@ 2026-09-16  7:17   ` Greg KH
  2026-09-16 10:19     ` Edward Adam Davis
  2026-09-17  7:34   ` Greg KH
  1 sibling, 1 reply; 13+ messages in thread
From: Greg KH @ 2026-09-16  7:17 UTC (permalink / raw)
  To: Edward Adam Davis
  Cc: syzbot+9a321aea9d851b299486, dakr, driver-core, linux-kernel,
	rafael, syzkaller-bugs

On Tue, Sep 15, 2026 at 08:20:17PM +0800, Edward Adam Davis wrote:
> Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> file write via sysfs_kf_write() may result in an out-of-bounds read when
> checking for the null terminator of a string element in the kobject_actions
> array within kobject_action_type(), potentially hitting:

What sysfs file are you hitting this on?

> 
> BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> Call Trace:
>  kobject_action_type lib/kobject_uevent.c:86 [inline]
>  kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
>  bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
>  bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
>  sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
>  kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
>  new_sync_write fs/read_write.c:595 [inline]
>  vfs_write+0x6af/0x1050 fs/read_write.c:687
> 
> Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> properly.
> 
> Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")

What changed to suddenly cause this to show up now if this has been
present for decades?

thanks,

greg k-h

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [PATCH] sysfs: prevent writing excessively large files
  2026-09-16  7:17   ` Greg KH
@ 2026-09-16 10:19     ` Edward Adam Davis
  2026-09-16 17:44       ` Greg KH
  0 siblings, 1 reply; 13+ messages in thread
From: Edward Adam Davis @ 2026-09-16 10:19 UTC (permalink / raw)
  To: gregkh
  Cc: dakr, driver-core, eadavis, linux-kernel, rafael,
	syzbot+9a321aea9d851b299486, syzkaller-bugs

From: Edward Aadm Davis <eadavis@sina.com>

On Wed, 16 Sep 2026 09:17:56 +0200, Greg KH wrote:
> > Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> > file write via sysfs_kf_write() may result in an out-of-bounds read when
> > checking for the null terminator of a string element in the kobject_actions
> > array within kobject_action_type(), potentially hitting:
> 
> What sysfs file are you hitting this on?
Regular sysfs files.
> 
> >
> > BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> > BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> > Call Trace:
> >  kobject_action_type lib/kobject_uevent.c:86 [inline]
> >  kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> >  bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
> >  bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
> >  sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
> >  kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
> >  new_sync_write fs/read_write.c:595 [inline]
> >  vfs_write+0x6af/0x1050 fs/read_write.c:687
> >
> > Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> > properly.
> >
> > Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
> 
> What changed to suddenly cause this to show up now if this has been
> present for decades?
This issue has always existed. It remained undetected simply because the
buffer lengths typically passed when writing to `/sys/bus/acpi/uevent`
happened to be reasonably appropriate.

cheers,
Edward

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [PATCH] sysfs: prevent writing excessively large files
  2026-09-16 10:19     ` Edward Adam Davis
@ 2026-09-16 17:44       ` Greg KH
  2026-09-17  4:24         ` Edward Adam Davis
  0 siblings, 1 reply; 13+ messages in thread
From: Greg KH @ 2026-09-16 17:44 UTC (permalink / raw)
  To: Edward Adam Davis
  Cc: dakr, driver-core, linux-kernel, rafael,
	syzbot+9a321aea9d851b299486, syzkaller-bugs

On Wed, Sep 16, 2026 at 06:19:30PM +0800, Edward Adam Davis wrote:
> From: Edward Aadm Davis <eadavis@sina.com>
> 
> On Wed, 16 Sep 2026 09:17:56 +0200, Greg KH wrote:
> > > Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> > > file write via sysfs_kf_write() may result in an out-of-bounds read when
> > > checking for the null terminator of a string element in the kobject_actions
> > > array within kobject_action_type(), potentially hitting:
> > 
> > What sysfs file are you hitting this on?
> Regular sysfs files.

Which one, all?

> > > BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> > > BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > > Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> > > Call Trace:
> > >  kobject_action_type lib/kobject_uevent.c:86 [inline]
> > >  kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > >  bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
> > >  bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
> > >  sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
> > >  kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
> > >  new_sync_write fs/read_write.c:595 [inline]
> > >  vfs_write+0x6af/0x1050 fs/read_write.c:687
> > >
> > > Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> > > properly.
> > >
> > > Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
> > 
> > What changed to suddenly cause this to show up now if this has been
> > present for decades?
> This issue has always existed. It remained undetected simply because the
> buffer lengths typically passed when writing to `/sys/bus/acpi/uevent`
> happened to be reasonably appropriate.

So what changed to cause this to show up now?

thanks,

greg k-h

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [PATCH] sysfs: prevent writing excessively large files
  2026-09-16 17:44       ` Greg KH
@ 2026-09-17  4:24         ` Edward Adam Davis
  0 siblings, 0 replies; 13+ messages in thread
From: Edward Adam Davis @ 2026-09-17  4:24 UTC (permalink / raw)
  To: gregkh
  Cc: dakr, driver-core, eadavis, linux-kernel, rafael,
	syzbot+9a321aea9d851b299486, syzkaller-bugs

From: Edward Aadm Davis <eadavis@sina.com>

On Wed, 16 Sep 2026 18:44:06 +0100, Greg KH wrote:
> On Wed, Sep 16, 2026 at 06:19:30PM +0800, Edward Adam Davis wrote:
> > From: Edward Aadm Davis <eadavis@sina.com>
> >
> > On Wed, 16 Sep 2026 09:17:56 +0200, Greg KH wrote:
> > > > Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> > > > file write via sysfs_kf_write() may result in an out-of-bounds read when
> > > > checking for the null terminator of a string element in the kobject_actions
> > > > array within kobject_action_type(), potentially hitting:
> > >
> > > What sysfs file are you hitting this on?
> > Regular sysfs files.
> 
> Which one, all?
/sys/bus/acpi/uevent
> 
> > > > BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> > > > BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > > > Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> > > > Call Trace:
> > > >  kobject_action_type lib/kobject_uevent.c:86 [inline]
> > > >  kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > > >  bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
> > > >  bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
> > > >  sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
> > > >  kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
> > > >  new_sync_write fs/read_write.c:595 [inline]
> > > >  vfs_write+0x6af/0x1050 fs/read_write.c:687
> > > >
> > > > Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> > > > properly.
> > > >
> > > > Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
> > >
> > > What changed to suddenly cause this to show up now if this has been
> > > present for decades?
> > This issue has always existed. It remained undetected simply because the
> > buffer lengths typically passed when writing to `/sys/bus/acpi/uevent`
> > happened to be reasonably appropriate.
> 
> So what changed to cause this to show up now?
Starting from f6acf8bb6a40.

cheers,
Edward

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [PATCH] sysfs: prevent writing excessively large files
  2026-09-15 12:20 ` [PATCH] sysfs: prevent writing excessively large files Edward Adam Davis
  2026-09-16  7:17   ` Greg KH
@ 2026-09-17  7:34   ` Greg KH
  2026-09-17  7:56     ` Edward Adam Davis
  2026-09-17 10:00     ` David Laight
  1 sibling, 2 replies; 13+ messages in thread
From: Greg KH @ 2026-09-17  7:34 UTC (permalink / raw)
  To: Edward Adam Davis
  Cc: syzbot+9a321aea9d851b299486, dakr, driver-core, linux-kernel,
	rafael, syzkaller-bugs

On Tue, Sep 15, 2026 at 08:20:17PM +0800, Edward Adam Davis wrote:
> Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> file write via sysfs_kf_write() may result in an out-of-bounds read when
> checking for the null terminator of a string element in the kobject_actions
> array within kobject_action_type(), potentially hitting:
> 
> BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> Call Trace:
>  kobject_action_type lib/kobject_uevent.c:86 [inline]
>  kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
>  bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
>  bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
>  sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
>  kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
>  new_sync_write fs/read_write.c:595 [inline]
>  vfs_write+0x6af/0x1050 fs/read_write.c:687
> 
> Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> properly.
> 
> Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
> Reported-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
> Tested-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
> Signed-off-by: Edward Adam Davis <eadavis@sina.com>
> ---
>  fs/sysfs/file.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
> index cd5bb0f9fee6..a63130d18680 100644
> --- a/fs/sysfs/file.c
> +++ b/fs/sysfs/file.c
> @@ -228,10 +228,12 @@ static const struct kernfs_ops sysfs_file_kfops_ro = {
>  };
>  
>  static const struct kernfs_ops sysfs_file_kfops_wo = {
> +	.atomic_write_len	= PAGE_SIZE,
>  	.write		= sysfs_kf_write,
>  };
>  
>  static const struct kernfs_ops sysfs_file_kfops_rw = {
> +	.atomic_write_len	= PAGE_SIZE,
>  	.seq_show	= sysfs_kf_seq_show,
>  	.write		= sysfs_kf_write,
>  };
> -- 
> 2.43.0
> 

Are you sure this will not break those sysfs files that want larger page
sizes?  Given the age of this "issue" it's really worrying to me to
change it now...

thanks,

greg k-h

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [PATCH] sysfs: prevent writing excessively large files
  2026-09-17  7:34   ` Greg KH
@ 2026-09-17  7:56     ` Edward Adam Davis
  2026-09-17 10:00     ` David Laight
  1 sibling, 0 replies; 13+ messages in thread
From: Edward Adam Davis @ 2026-09-17  7:56 UTC (permalink / raw)
  To: gregkh
  Cc: dakr, driver-core, eadavis, linux-kernel, rafael,
	syzbot+9a321aea9d851b299486, syzkaller-bugs

From: Edward Aadm Davis <eadavis@sina.com>

On Thu, 17 Sep 2026 08:34:46 +0100, Greg KH wrote:
> > Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> > file write via sysfs_kf_write() may result in an out-of-bounds read when
> > checking for the null terminator of a string element in the kobject_actions
> > array within kobject_action_type(), potentially hitting:
> >
> > BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> > BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> > Call Trace:
> >  kobject_action_type lib/kobject_uevent.c:86 [inline]
> >  kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> >  bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
> >  bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
> >  sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
> >  kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
> >  new_sync_write fs/read_write.c:595 [inline]
> >  vfs_write+0x6af/0x1050 fs/read_write.c:687
> >
> > Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> > properly.
> >
> > Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
> > Reported-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
> > Closes: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
> > Tested-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
> > Signed-off-by: Edward Adam Davis <eadavis@sina.com>
> > ---
> >  fs/sysfs/file.c | 2 ++
> >  1 file changed, 2 insertions(+)
> >
> > diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
> > index cd5bb0f9fee6..a63130d18680 100644
> > --- a/fs/sysfs/file.c
> > +++ b/fs/sysfs/file.c
> > @@ -228,10 +228,12 @@ static const struct kernfs_ops sysfs_file_kfops_ro = {
> >  };
> >
> >  static const struct kernfs_ops sysfs_file_kfops_wo = {
> > +	.atomic_write_len	= PAGE_SIZE,
> >  	.write		= sysfs_kf_write,
> >  };
> >
> >  static const struct kernfs_ops sysfs_file_kfops_rw = {
> > +	.atomic_write_len	= PAGE_SIZE,
> >  	.seq_show	= sysfs_kf_seq_show,
> >  	.write		= sysfs_kf_write,
> >  };
> > --
> > 2.43.0
> >
> 
> Are you sure this will not break those sysfs files that want larger page
> sizes?  Given the age of this "issue" it's really worrying to me to
> change it now...
Perhaps it would be better to make a decision after delving deeper into
the details.

cheers,
Edward

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: [PATCH] sysfs: prevent writing excessively large files
  2026-09-17  7:34   ` Greg KH
  2026-09-17  7:56     ` Edward Adam Davis
@ 2026-09-17 10:00     ` David Laight
  1 sibling, 0 replies; 13+ messages in thread
From: David Laight @ 2026-09-17 10:00 UTC (permalink / raw)
  To: Greg KH
  Cc: Edward Adam Davis, syzbot+9a321aea9d851b299486, dakr,
	driver-core, linux-kernel, rafael, syzkaller-bugs

On Thu, 17 Sep 2026 08:34:46 +0100
Greg KH <gregkh@linuxfoundation.org> wrote:

> On Tue, Sep 15, 2026 at 08:20:17PM +0800, Edward Adam Davis wrote:
> > Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> > file write via sysfs_kf_write() may result in an out-of-bounds read when
> > checking for the null terminator of a string element in the kobject_actions
> > array within kobject_action_type(), potentially hitting:
> > 
> > BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> > BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> > Call Trace:
> >  kobject_action_type lib/kobject_uevent.c:86 [inline]
> >  kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> >  bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
> >  bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
> >  sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
> >  kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
> >  new_sync_write fs/read_write.c:595 [inline]
> >  vfs_write+0x6af/0x1050 fs/read_write.c:687
> > 
> > Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> > properly.
> > 
> > Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
> > Reported-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
> > Closes: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
> > Tested-by: syzbot+9a321aea9d851b299486@syzkaller.appspotmail.com
> > Signed-off-by: Edward Adam Davis <eadavis@sina.com>
> > ---
> >  fs/sysfs/file.c | 2 ++
> >  1 file changed, 2 insertions(+)
> > 
> > diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
> > index cd5bb0f9fee6..a63130d18680 100644
> > --- a/fs/sysfs/file.c
> > +++ b/fs/sysfs/file.c
> > @@ -228,10 +228,12 @@ static const struct kernfs_ops sysfs_file_kfops_ro = {
> >  };
> >  
> >  static const struct kernfs_ops sysfs_file_kfops_wo = {
> > +	.atomic_write_len	= PAGE_SIZE,
> >  	.write		= sysfs_kf_write,
> >  };
> >  
> >  static const struct kernfs_ops sysfs_file_kfops_rw = {
> > +	.atomic_write_len	= PAGE_SIZE,
> >  	.seq_show	= sysfs_kf_seq_show,
> >  	.write		= sysfs_kf_write,
> >  };
> > -- 
> > 2.43.0
> >   
> 
> Are you sure this will not break those sysfs files that want larger page
> sizes?  Given the age of this "issue" it's really worrying to me to
> change it now...

If you allowed to leave atomic_write_len as zero then the code shouldn't
let an overlong write through (or should truncate it).
So there must be a bug somewhere else.

Do we know the length for the test that failed?

'atomic_write_len' is also badly named - probably historical.
There is no code to loop over the fragments of a long write and (IIRC) the
write offset is always zero.

There is also some (horrid) related code that can reserve a page buffer
(per node) just in case an access is made when kernel memory isn't
available.
(a flag and a single global page would suffice...)

David


> 
> thanks,
> 
> greg k-h
> 


^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-09-17 10:00 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-14 16:38 [syzbot] [kernel?] KASAN: global-out-of-bounds Read in bus_uevent_store syzbot
2026-09-15 11:00 ` Edward Adam Davis
2026-09-15 11:22   ` syzbot
2026-09-15 11:24 ` Edward Adam Davis
2026-09-15 12:06   ` syzbot
2026-09-15 12:20 ` [PATCH] sysfs: prevent writing excessively large files Edward Adam Davis
2026-09-16  7:17   ` Greg KH
2026-09-16 10:19     ` Edward Adam Davis
2026-09-16 17:44       ` Greg KH
2026-09-17  4:24         ` Edward Adam Davis
2026-09-17  7:34   ` Greg KH
2026-09-17  7:56     ` Edward Adam Davis
2026-09-17 10:00     ` David Laight

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®