From: Greg KH <gregkh@linuxfoundation.org>
To: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Cc: rafael@kernel.org, dakr@kernel.org, johan@kernel.org,
driver-core@lists.linux.dev, linux-kernel@vger.kernel.org,
stable@vger.kernel.org, "sashiko . dev" <sashiko-bot@kernel.org>
Subject: Re: [PATCH v4 1/2] debugfs: fix use-after-free in debugfs_read_file_str()
Date: Sun, 27 Sep 2026 18:37:40 +0200 [thread overview]
Message-ID: <2026092720-sandblast-heroism-30c8@gregkh> (raw)
In-Reply-To: <20260926195844.1296333-2-qwe.aldo@gmail.com>
On Sat, Sep 26, 2026 at 04:58:43PM -0300, Aldo Ariel Panzardo wrote:
> debugfs_write_file_str() publishes a new string pointer via
> rcu_assign_pointer(), waits for a grace period with synchronize_rcu(),
> then frees the old string.
>
> debugfs_read_file_str() dereferences file->private_data without holding
> an RCU read-side critical section: it loads the pointer, calls strlen()
> on it, and then copies the string. If a concurrent writer completes
> synchronize_rcu() and kfree()s the old string between the load and the
> use, the reader accesses freed memory.
>
> Fix by measuring the string length under rcu_read_lock(), allocating
> with GFP_KERNEL outside the critical section, and then copying with
> strscpy() under a second rcu_read_lock(). If the current string no
> longer fits the allocated buffer, retry with a PAGE_SIZE allocation
> which is the upper bound enforced by the write path.
Please don't use a LLM to write a changelog text without crediting it :(
>
> Cc: stable@vger.kernel.org
> Assisted-by: sashiko.dev <sashiko-bot@kernel.org>
> Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
> ---
> fs/debugfs/file.c | 39 +++++++++++++++++++++++++--------------
> 1 file changed, 25 insertions(+), 14 deletions(-)
>
> diff --git a/fs/debugfs/file.c b/fs/debugfs/file.c
> index 08de6652a..f9a1f7739 100644
> --- a/fs/debugfs/file.c
> +++ b/fs/debugfs/file.c
> @@ -1018,7 +1018,7 @@ ssize_t debugfs_read_file_str(struct file *file, char __user *user_buf,
> size_t count, loff_t *ppos)
> {
> struct dentry *dentry = F_DENTRY(file);
> - char *str, *copy = NULL;
> + char *str, *copy;
> int copy_len, len;
> ssize_t ret;
>
> @@ -1026,26 +1026,37 @@ ssize_t debugfs_read_file_str(struct file *file, char __user *user_buf,
> if (unlikely(ret))
> return ret;
>
> - str = *(char **)file->private_data;
> - len = strlen(str) + 1;
> - copy = kmalloc(len, GFP_KERNEL);
> - if (!copy) {
> - debugfs_file_put(dentry);
> - return -ENOMEM;
> - }
> + len = 0;
> + for (;;) {
This is probably not right, don't do loops like this. Either fail or
succeed, don't loop.
Again, let's see the real use case here, what is hitting this in
userspace today and what debugfs kernel files are causing it?
thanks,
greg k-h
next prev parent reply other threads:[~2026-09-27 16:37 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <DLPDB44JJRGJ.3K6JNS746M71C@kernel.org>
2026-09-26 19:58 ` [PATCH v4 0/2] debugfs: fix UAF and double-free in debugfs_str read/write Aldo Ariel Panzardo
2026-09-26 19:58 ` [PATCH v4 1/2] debugfs: fix use-after-free in debugfs_read_file_str() Aldo Ariel Panzardo
2026-09-27 16:37 ` Greg KH [this message]
2026-09-27 17:00 ` Danilo Krummrich
2026-09-28 5:35 ` Greg KH
2026-09-28 8:26 ` Danilo Krummrich
2026-09-27 20:31 ` Aldo Ariel Panzardo
2026-09-26 19:58 ` [PATCH v4 2/2] debugfs: serialize concurrent writers in debugfs_write_file_str() Aldo Ariel Panzardo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026092720-sandblast-heroism-30c8@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=dakr@kernel.org \
--cc=driver-core@lists.linux.dev \
--cc=johan@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=qwe.aldo@gmail.com \
--cc=rafael@kernel.org \
--cc=sashiko-bot@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®