mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] fs/ntfs3: fix memory leak in ntfs_fill_super()
@ 2025-12-11 13:51 Konstantin Komarov
  2025-12-11 14:33 ` Konstantin Komarov
  0 siblings, 1 reply; 3+ messages in thread
From: Konstantin Komarov @ 2025-12-11 13:51 UTC (permalink / raw)
  To: ntfs3; +Cc: linux-kernel, linux-fsdevel, Konstantin Komarov

ntfs_fill_super() assigns fc->fs_private to a newly allocated options
structure earlier in the mount path. At the end of a successful mount, the
code set fc->fs_private = NULL, which prevented the vfs from freeing this
memory during mount context cleanup. As a result, the options structure
was leaked.

Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
---
 fs/ntfs3/super.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/fs/ntfs3/super.c b/fs/ntfs3/super.c
index a641d474c782..38d82e46171a 100644
--- a/fs/ntfs3/super.c
+++ b/fs/ntfs3/super.c
@@ -1252,7 +1252,6 @@ static int ntfs_fill_super(struct super_block *sb, struct fs_context *fc)
 		}
 	}
 	sbi->options = options;
-	fc->fs_private = NULL;
 	sb->s_flags |= SB_NODIRATIME;
 	sb->s_magic = 0x7366746e; // "ntfs"
 	sb->s_op = &ntfs_sops;
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] fs/ntfs3: fix memory leak in ntfs_fill_super()
  2025-12-11 13:51 [PATCH] fs/ntfs3: fix memory leak in ntfs_fill_super() Konstantin Komarov
@ 2025-12-11 14:33 ` Konstantin Komarov
  0 siblings, 0 replies; 3+ messages in thread
From: Konstantin Komarov @ 2025-12-11 14:33 UTC (permalink / raw)
  To: ntfs3; +Cc: linux-kernel, linux-fsdevel

On 12/11/25 14:51, Konstantin Komarov wrote:

> ntfs_fill_super() assigns fc->fs_private to a newly allocated options
> structure earlier in the mount path. At the end of a successful mount, the
> code set fc->fs_private = NULL, which prevented the vfs from freeing this
> memory during mount context cleanup. As a result, the options structure
> was leaked.
>
> Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
> ---
>   fs/ntfs3/super.c | 1 -
>   1 file changed, 1 deletion(-)
>
> diff --git a/fs/ntfs3/super.c b/fs/ntfs3/super.c
> index a641d474c782..38d82e46171a 100644
> --- a/fs/ntfs3/super.c
> +++ b/fs/ntfs3/super.c
> @@ -1252,7 +1252,6 @@ static int ntfs_fill_super(struct super_block *sb, struct fs_context *fc)
>   		}
>   	}
>   	sbi->options = options;
> -	fc->fs_private = NULL;
>   	sb->s_flags |= SB_NODIRATIME;
>   	sb->s_magic = 0x7366746e; // "ntfs"
>   	sb->s_op = &ntfs_sops;

Please withdraw this patch.

I realized after sending it that an equivalent patch was already submitted
earlier by Baokun Li<libaokun1@huawei.com>. My version is redundant, so I
will drop it and proceed with reviewing/merging the earlier contribution.

Apologies for the duplication.

Regards,
Konstantin


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH] fs/ntfs3: Fix memory leak in ntfs_fill_super()
@ 2023-09-16 17:58 Shigeru Yoshida
  0 siblings, 0 replies; 3+ messages in thread
From: Shigeru Yoshida @ 2023-09-16 17:58 UTC (permalink / raw)
  To: almaz.alexandrovich
  Cc: ntfs3, linux-kernel, Shigeru Yoshida, syzbot+9ccdd15480e9d9833822

syzbot reported memory leak in ntfs_fill_super(). ntfs_fill_super() calls
wnd_init() and this allocates memory. So, we need to free those memory on the
error handling path in ntfs_fill_super().

Fixes: 82cae269cfa9 ("fs/ntfs3: Add initialization of super block")
Reported-and-tested-by: syzbot+9ccdd15480e9d9833822@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9ccdd15480e9d9833822
Signed-off-by: Shigeru Yoshida <syoshida@redhat.com>
---
 fs/ntfs3/super.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/fs/ntfs3/super.c b/fs/ntfs3/super.c
index cfec5e0c7f66..a9610f5f4cc0 100644
--- a/fs/ntfs3/super.c
+++ b/fs/ntfs3/super.c
@@ -1563,6 +1563,13 @@ static int ntfs_fill_super(struct super_block *sb, struct fs_context *fc)
 	iput(inode);
 out:
 	kfree(boot2);
+
+	if (sbi->mft.bitmap.inited)
+		wnd_close(&sbi->mft.bitmap);
+
+	if (sbi->used.bitmap.inited)
+		wnd_close(&sbi->used.bitmap);
+
 	return err;
 }
 
-- 
2.41.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2025-12-11 14:33 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-12-11 13:51 [PATCH] fs/ntfs3: fix memory leak in ntfs_fill_super() Konstantin Komarov
2025-12-11 14:33 ` Konstantin Komarov
  -- strict thread matches above, loose matches on Subject: below --
2023-09-16 17:58 [PATCH] fs/ntfs3: Fix " Shigeru Yoshida

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®