mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kazuki Hanai <hnkz.64@gmail.com>
To: hughd@google.com
Cc: Kazuki Hanai <hnkz.64@gmail.com>,
	baolin.wang@linux.alibaba.com, akpm@linux-foundation.org,
	gabriel@krisman.be, andrealmeid@igalia.com, brauner@kernel.org,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org
Subject: [PATCH v3] tmpfs: fix unicode_map leaks in casefold option handling
Date: Fri,  2 Oct 2026 17:13:03 +0900	[thread overview]
Message-ID: <20261002081306.637148-1-hnkz.64@gmail.com> (raw)
In-Reply-To: <20260827152516.805622-1-hnkz.64@gmail.com>

shmem_parse_opt_casefold() stores the unicode_map returned by
utf8_load() in ctx->encoding. A filesystem context can receive the
casefold parameter more than once, and a second successful parse
overwrites the stored map without releasing it.

The map is also leaked when an unmounted filesystem context is freed.
This includes the temporary context used for remount, because
shmem_reconfigure() does not take ownership of ctx->encoding.

Reject a second casefold setting, clear ctx->encoding after transferring
ownership to the superblock, and release any remaining map from
shmem_free_fc().

An unprivileged user can repeatedly create tmpfs filesystem contexts,
set the casefold parameter, and close them from a user namespace. This
causes unbounded kernel memory consumption and can result in a local
denial of service.

Fixes: 58e55efd6c72 ("tmpfs: Add casefold lookup support")
Cc: stable@vger.kernel.org
Suggested-by: Gabriel Krisman Bertazi <gabriel@krisman.be>
Signed-off-by: Kazuki Hanai <hnkz.64@gmail.com>
---
Changes in v3:
- Reject a second casefold option instead of unloading and replacing the
  first map, as suggested by Gabriel.
- Reword the commit message to describe the remount and close paths.

Changes in v2:
- Keep Fixes, Cc, and Signed-off-by in a single trailer block.

 mm/shmem.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/mm/shmem.c b/mm/shmem.c
index 848316eaa7f4fb..1bd004c3dde20b 100644
--- a/mm/shmem.c
+++ b/mm/shmem.c
@@ -4509,6 +4509,9 @@ static int shmem_parse_opt_casefold(struct fs_context *fc, struct fs_parameter *
 	struct unicode_map *encoding;
 	char *version_str = param->string + 5;
 
+	if (ctx->encoding)
+		return invalfc(fc, "casefold parameter cannot be specified twice\n");
+
 	if (!latest_version) {
 		if (strncmp(param->string, "utf8-", 5))
 			return invalfc(fc, "Only UTF-8 encodings are supported "
@@ -4998,6 +5001,7 @@ static int shmem_fill_super(struct super_block *sb, struct fs_context *fc)
 
 	if (ctx->encoding) {
 		sb->s_encoding = ctx->encoding;
+		ctx->encoding = NULL;
 		set_default_d_op(sb, &shmem_ci_dentry_ops);
 		if (ctx->strict_encoding)
 			sb->s_encoding_flags = SB_ENC_STRICT_MODE_FL;
@@ -5095,6 +5099,9 @@ static void shmem_free_fc(struct fs_context *fc)
 	struct shmem_options *ctx = fc->fs_private;
 
 	if (ctx) {
+#if IS_ENABLED(CONFIG_UNICODE)
+		utf8_unload(ctx->encoding);
+#endif
 		mpol_put(ctx->mpol);
 		kfree(ctx);
 	}
-- 
2.53.0

      parent reply	other threads:[~2026-10-02  8:13 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-27 15:14 [PATCH] " Kazuki Hanai
2026-08-27 15:25 ` [PATCH v2] " Kazuki Hanai
2026-08-27 17:29   ` Andrew Morton
2026-09-29 21:09   ` Gabriel Krisman Bertazi
2026-10-02  8:13   ` Kazuki Hanai [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002081306.637148-1-hnkz.64@gmail.com \
    --to=hnkz.64@gmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=andrealmeid@igalia.com \
    --cc=baolin.wang@linux.alibaba.com \
    --cc=brauner@kernel.org \
    --cc=gabriel@krisman.be \
    --cc=hughd@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®