* [syzbot] [dm?] KASAN: wild-memory-access Write in __journal_read_write
@ 2026-09-30 14:25 syzbot
2026-09-30 16:42 ` [PATCH] dm-integrity: validate the superblock on resume Mikulas Patocka
0 siblings, 1 reply; 2+ messages in thread
From: syzbot @ 2026-09-30 14:25 UTC (permalink / raw)
To: agk, bmarzins, dm-devel, linux-kernel, mpatocka, snitzer, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: 551c722f4080 Merge tag 'rtc-7.3-fixes' of git://git.kernel..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=1111c6c9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7d012d9c67977ee4
dashboard link: https://syzkaller.appspot.com/bug?extid=675c91651049ad042c5f
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=171b0035580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+675c91651049ad042c5f@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: wild-memory-access in __journal_read_write+0xc29/0x1f10 drivers/md/dm-integrity.c:2288
Write of size 512 at addr 0005088000000000 by task syz-executor338/6039
CPU: 0 UID: 0 PID: 6039 Comm: syz-executor338 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
check_region_inline mm/kasan/generic.c:186 [inline]
kasan_check_range+0x10f/0x1e0 mm/kasan/generic.c:200
__asan_memcpy+0x3c/0x60 mm/kasan/shadow.c:106
__journal_read_write+0xc29/0x1f10 drivers/md/dm-integrity.c:2288
dm_integrity_map_continue+0x243f/0x33b0 drivers/md/dm-integrity.c:2574
dm_integrity_map+0x6cc/0xc90 drivers/md/dm-integrity.c:2204
__map_bio+0x597/0x660 drivers/md/dm.c:1435
__split_and_process_bio drivers/md/dm.c:1769 [inline]
dm_split_and_process_bio drivers/md/dm.c:2043 [inline]
dm_submit_bio+0x5b6/0x2950 drivers/md/dm.c:2099
__submit_bio block/blk-core.c:681 [inline]
__submit_bio+0x20e/0x3d0 block/blk-core.c:670
__submit_bio_noacct block/blk-core.c:724 [inline]
submit_bio_noacct_nocheck+0x736/0xc00 block/blk-core.c:792
submit_bio_noacct+0xc93/0x2130 block/blk-core.c:925
bio_await+0x1fa/0x240 block/bio.c:1581
submit_bio_wait+0x19/0x60 block/bio.c:1599
__blkdev_direct_IO_simple+0x4cb/0x8c0 block/fops.c:98
blkdev_direct_IO+0xbee/0x2030 block/fops.c:429
blkdev_direct_write block/fops.c:699 [inline]
blkdev_write_iter+0x703/0xd30 block/fops.c:767
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x6af/0x1050 fs/read_write.c:687
ksys_pwrite64 fs/read_write.c:794 [inline]
__do_sys_pwrite64 fs/read_write.c:802 [inline]
__se_sys_pwrite64 fs/read_write.c:799 [inline]
__x64_sys_pwrite64+0x1eb/0x250 fs/read_write.c:799
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x123/0x790 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f5408351ab7
Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffc07ac8820 EFLAGS: 00000202 ORIG_RAX: 0000000000000012
RAX: ffffffffffffffda RBX: 0000555592860400 RCX: 00007f5408351ab7
RDX: 0000000000000400 RSI: 0000555592863000 RDI: 0000000000000007
RBP: 0000000000000003 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 00005555928627a0
R13: 0000000000000007 R14: 0000555592863000 R15: 00000000c138fd06
</TASK>
==================================================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH] dm-integrity: validate the superblock on resume
2026-09-30 14:25 [syzbot] [dm?] KASAN: wild-memory-access Write in __journal_read_write syzbot
@ 2026-09-30 16:42 ` Mikulas Patocka
0 siblings, 0 replies; 2+ messages in thread
From: Mikulas Patocka @ 2026-09-30 16:42 UTC (permalink / raw)
To: syzbot; +Cc: agk, bmarzins, dm-devel, linux-kernel, snitzer, syzkaller-bugs
On Wed, 30 Sep 2026, syzbot wrote:
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 551c722f4080 Merge tag 'rtc-7.3-fixes' of git://git.kernel..
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
> console output: https://syzkaller.appspot.com/x/log.txt?x=1111c6c9580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=7d012d9c67977ee4
> dashboard link: https://syzkaller.appspot.com/bug?extid=675c91651049ad042c5f
> compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=171b0035580000
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+675c91651049ad042c5f@syzkaller.appspotmail.com
Hi
Here I'm sending a patch for this bug.
Mikulas
From: Mikulas Patocka <mpatocka@redhat.com>
dm_integrity_resume() re-reads the superblock from the device so that it
picks up the flags and the recalculate position. It performs no
validation on the result, while the constructor validates the superblock
it reads and sizes all the in-memory structures according to it. The user
may modify the superblock on the underlying device while the dm-integrity
device is suspended, so that the two no longer agree.
In particular, access_journal_data() shifts the journal entry index by
ic->sb->log2_sectors_per_block, while ic->journal_section_sectors and the
journal page list were computed with the value that was present at
constructor time. Increasing log2_sectors_per_block makes the index run
past the end of the journal, and dm-integrity then writes 512 bytes
through lowmem_page_address(NULL).
Snapshot the validated superblock in the constructor and refuse to resume
if any of the fields that describe the on-disk geometry changed.
Reported-by: syzbot+675c91651049ad042c5f@syzkaller.appspotmail.com
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Cc: stable@vger.kernel.org
Fixes: 118ba36e446c ("dm-integrity: fix recalculation in bitmap mode")
Assisted-by: Claude:claude-opus-5
---
drivers/md/dm-integrity.c | 50 ++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 50 insertions(+)
Index: linux-2.6/drivers/md/dm-integrity.c
===================================================================
--- linux-2.6.orig/drivers/md/dm-integrity.c
+++ linux-2.6/drivers/md/dm-integrity.c
@@ -180,6 +180,7 @@ struct dm_integrity_c {
struct dm_bufio_client *bufio;
struct workqueue_struct *metadata_wq;
struct superblock *sb;
+ struct superblock *sb_copy;
unsigned int journal_pages;
unsigned int n_bitmap_blocks;
@@ -3858,6 +3859,35 @@ static void dm_integrity_postsuspend(str
ic->journal_uptodate = true;
}
+/*
+ * The superblock is re-read from the device on every resume, so that we pick
+ * up the flags and the recalculate position. The geometry described by the
+ * superblock must not change though - the in-memory structures (and the
+ * journal in particular) were sized according to the superblock that was
+ * validated in the constructor. Reject a superblock that was modified behind
+ * our back.
+ *
+ * Only the fields that the driver never rewrites may be tested here. In
+ * particular, "version" is recalculated by sb_set_version on every superblock
+ * write and it depends on SB_FLAG_RECALCULATING and SB_FLAG_DIRTY_BITMAP, and
+ * SB_FLAG_DISCARD_KEYED may be set by dm_integrity_resume itself.
+ */
+static bool superblock_changed(struct dm_integrity_c *ic)
+{
+ const __le32 immutable_flags = cpu_to_le32(SB_FLAG_HAVE_JOURNAL_MAC |
+ SB_FLAG_FIXED_PADDING |
+ SB_FLAG_FIXED_HMAC |
+ SB_FLAG_INLINE);
+
+ return memcmp(ic->sb->magic, ic->sb_copy->magic, sizeof(ic->sb->magic)) != 0 ||
+ ic->sb->log2_interleave_sectors != ic->sb_copy->log2_interleave_sectors ||
+ ic->sb->integrity_tag_size != ic->sb_copy->integrity_tag_size ||
+ ic->sb->journal_sections != ic->sb_copy->journal_sections ||
+ ic->sb->log2_sectors_per_block != ic->sb_copy->log2_sectors_per_block ||
+ ((ic->sb->flags ^ ic->sb_copy->flags) & immutable_flags) != 0 ||
+ memcmp(ic->sb->salt, ic->sb_copy->salt, SALT_SIZE) != 0;
+}
+
static void dm_integrity_resume(struct dm_target *ti)
{
struct dm_integrity_c *ic = ti->private;
@@ -3876,6 +3906,18 @@ static void dm_integrity_resume(struct d
if (r)
dm_integrity_io_error(ic, "reading superblock", r);
+ if (unlikely(superblock_changed(ic))) {
+ /*
+ * Restore the superblock that we validated in the constructor,
+ * so that the rest of the driver doesn't operate on values
+ * that don't match the in-memory structures.
+ */
+ memcpy(ic->sb, ic->sb_copy, sizeof(struct superblock));
+ DMERR("The superblock was changed while the device was suspended");
+ dm_integrity_io_error(ic, "superblock check", -EINVAL);
+ goto skip_writes;
+ }
+
if (ic->mode == 'R')
goto skip_writes;
@@ -5427,6 +5469,13 @@ try_smaller_buffer:
ic->just_formatted = true;
}
+ ic->sb_copy = kmemdup(ic->sb, sizeof(struct superblock), GFP_KERNEL);
+ if (!ic->sb_copy) {
+ ti->error = "Cannot allocate superblock copy";
+ r = -ENOMEM;
+ goto bad;
+ }
+
if (!ic->meta_dev && ic->mode != 'I') {
r = dm_set_target_max_io_len(ti, 1U << ic->sb->log2_interleave_sectors);
if (r)
@@ -5525,6 +5574,7 @@ static void dm_integrity_dtr(struct dm_t
kvfree(ic->journal_tree);
if (ic->sb)
free_pages_exact(ic->sb, SB_SECTORS << SECTOR_SHIFT);
+ kfree(ic->sb_copy);
if (ic->internal_shash)
crypto_free_shash(ic->internal_shash);
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-30 16:42 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 14:25 [syzbot] [dm?] KASAN: wild-memory-access Write in __journal_read_write syzbot
2026-09-30 16:42 ` [PATCH] dm-integrity: validate the superblock on resume Mikulas Patocka
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®