* Re: [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
@ 2026-09-29 0:32 ` syzbot
2026-09-29 1:00 ` Qu Wenruo
2026-10-01 19:48 ` Forwarded: [PATCH] ext4: validate dirents before splitting a directory syzbot
` (2 subsequent siblings)
3 siblings, 1 reply; 6+ messages in thread
From: syzbot @ 2026-09-29 0:32 UTC (permalink / raw)
To: adilger.kernel, boris, dsterba, dsterba, fdmanana, jack,
libaokun, linux-ext4, linux-kernel, ojaswin, ritesh.list,
syzkaller-bugs, tytso, wqu, yi.zhang
syzbot has bisected this issue to:
commit 3f757b56f1c4579fe32b810bce1d39f202964412
Author: Filipe Manana <fdmanana@suse.com>
Date: Fri May 16 16:07:40 2025 +0000
btrfs: unfold transaction aborts at btrfs_create_new_inode()
bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=16bbf315580000
start commit: 72d3fcf802c4 Linux 7.3-rc5
git tree: upstream
final oops: https://syzkaller.appspot.com/x/report.txt?x=15bbf315580000
console output: https://syzkaller.appspot.com/x/log.txt?x=11bbf315580000
kernel config: https://syzkaller.appspot.com/x/.config?x=718e346eb0b8f38
dashboard link: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12379605580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=127f6325580000
Reported-by: syzbot+09bec78ee77613a3efdd@syzkaller.appspotmail.com
Fixes: 3f757b56f1c4 ("btrfs: unfold transaction aborts at btrfs_create_new_inode()")
For information about bisection process see: https://goo.gl/tpsmEJ#bisection
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split
2026-09-29 0:32 ` syzbot
@ 2026-09-29 1:00 ` Qu Wenruo
0 siblings, 0 replies; 6+ messages in thread
From: Qu Wenruo @ 2026-09-29 1:00 UTC (permalink / raw)
To: syzbot, adilger.kernel, boris, dsterba, dsterba, fdmanana, jack,
libaokun, linux-ext4, linux-kernel, ojaswin, ritesh.list,
syzkaller-bugs, tytso, yi.zhang
在 2026/9/29 10:02, syzbot 写道:
> syzbot has bisected this issue to:
>
> commit 3f757b56f1c4579fe32b810bce1d39f202964412
> Author: Filipe Manana <fdmanana@suse.com>
> Date: Fri May 16 16:07:40 2025 +0000
>
> btrfs: unfold transaction aborts at btrfs_create_new_inode()
This bisection doesn't make any sense.
The console output is showing ext4_add_entry()->do_split() causing the
KASAN.
Furthermore, there is no btrfs in the whole console output.
There must be some randomness in the reproducer.
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=16bbf315580000
> start commit: 72d3fcf802c4 Linux 7.3-rc5
> git tree: upstream
> final oops: https://syzkaller.appspot.com/x/report.txt?x=15bbf315580000
> console output: https://syzkaller.appspot.com/x/log.txt?x=11bbf315580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=718e346eb0b8f38
> dashboard link: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12379605580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=127f6325580000
>
> Reported-by: syzbot+09bec78ee77613a3efdd@syzkaller.appspotmail.com
> Fixes: 3f757b56f1c4 ("btrfs: unfold transaction aborts at btrfs_create_new_inode()")
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection
^ permalink raw reply [flat|nested] 6+ messages in thread
* Forwarded: [PATCH] ext4: validate dirents before splitting a directory
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
2026-09-29 0:32 ` syzbot
@ 2026-10-01 19:48 ` syzbot
2026-10-01 20:34 ` Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents() syzbot
2026-10-01 21:30 ` syzbot
3 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-10-01 19:48 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: validate dirents before splitting a directory
Author: adrianox@gmail.com
#syz test: upstream master
syzbot reported a slab-use-after-free write in do_split() while
renaming an entry in a directory that is being converted into an
indexed (htree) directory by make_indexed_dir():
BUG: KASAN: slab-use-after-free in dx_move_dirents [inline]
BUG: KASAN: slab-use-after-free in do_split+0x1241/0x1e90
Write of size 90458 at addr ffff88803b38ac6e by task syz.0.17/6003
do_split() builds a map of the leaf's dirents and then moves a subset
of them to a new block. dx_move_dirents() trusts map[i].offs and uses
the rec_len found there as the length of a memset(). With a corrupted
or crafted directory block, a bogus map entry makes that rec_len
garbage (here 90464), turning the memset() into an out-of-bounds write
that can corrupt arbitrary memory.
Validate each entry that is about to be moved with
ext4_check_dir_entry() before using it, and bail out with
-EFSCORRUPTED if the entry does not lie inside the block. This is the
same class of validation already used elsewhere in the directory code.
This is a filesystem-corruption hardening issue; the crash needs a
corrupt directory, which is why it is not reachable on a consistent
filesystem. The syzbot "introduced by" bisection pointed at an
unrelated btrfs commit and can be ignored.
Closes: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
---
fs/ext4/namei.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index a6386c1d237f..b2ec222b15e4 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -1951,6 +1951,25 @@ static struct ext4_dir_entry_2 *do_split(handle_t *handle, struct inode *dir,
goto journal_error;
}
map -= count;
+ /*
+ * The map is built from the on-disk dirents, so its entries should
+ * always refer to valid dirents. However, if the leaf block is
+ * corrupted (e.g. a crafted image), a bogus map entry can make
+ * dx_move_dirents() read a rec_len from an arbitrary location and use
+ * it as the length of a memset(), writing far out of bounds. Validate
+ * every entry we are about to move before using it.
+ */
+ for (i = 0; i < count; i++) {
+ unsigned int off = map[i].offs << 2;
+
+ if (off > blocksize - sizeof(struct ext4_dir_entry_2) ||
+ ext4_check_dir_entry(dir, NULL,
+ (struct ext4_dir_entry_2 *)(data1 + off),
+ *bh, data1, blocksize, off)) {
+ err = -EFSCORRUPTED;
+ goto out;
+ }
+ }
dx_sort_map(map, count);
/* Ensure that neither split block is over half full */
size = 0;
--
2.51.0
^ permalink raw reply [flat|nested] 6+ messages in thread* Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
2026-09-29 0:32 ` syzbot
2026-10-01 19:48 ` Forwarded: [PATCH] ext4: validate dirents before splitting a directory syzbot
@ 2026-10-01 20:34 ` syzbot
2026-10-01 21:30 ` syzbot
3 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-10-01 20:34 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
Author: adrianox@gmail.com
#syz test: upstream master
---
fs/ext4/namei.c | 38 ++++++++++++++++++++++++++++++--------
1 file changed, 30 insertions(+), 8 deletions(-)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index a6386c1d237f..83e4564f9f44 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -1840,30 +1840,46 @@ struct dentry *ext4_get_parent(struct dentry *child)
/*
* Move count entries from end of map between two memory locations.
- * Returns pointer to last entry moved.
+ * Returns pointer to last entry moved or an ERR_PTR on a corrupt entry.
*/
static struct ext4_dir_entry_2 *
dx_move_dirents(struct inode *dir, char *from, char *to,
struct dx_map_entry *map, int count,
unsigned blocksize)
{
+ char *to_start = to;
unsigned rec_len = 0;
while (count--) {
- struct ext4_dir_entry_2 *de = (struct ext4_dir_entry_2 *)
- (from + (map->offs<<2));
+ unsigned int off = map->offs << 2;
+ struct ext4_dir_entry_2 *de;
+
+ /*
+ * The map is built from on-disk dirents, but a corrupted or
+ * concurrently reused leaf block can still make an entry point
+ * outside the block. Never dereference such an entry.
+ */
+ if (off > blocksize - sizeof(struct ext4_dir_entry_2))
+ return ERR_PTR(-EFSCORRUPTED);
+ de = (struct ext4_dir_entry_2 *)(from + off);
rec_len = ext4_dir_rec_len(de->name_len, dir);
+ if (off + rec_len > blocksize ||
+ to + rec_len > to_start + blocksize)
+ return ERR_PTR(-EFSCORRUPTED);
memcpy (to, de, rec_len);
((struct ext4_dir_entry_2 *) to)->rec_len =
ext4_rec_len_to_disk(rec_len, blocksize);
- /* wipe dir_entry excluding the rec_len field */
+ /*
+ * Wipe dir_entry excluding the rec_len field. Use the entry's
+ * own (minimal) length instead of the untrusted on-disk rec_len,
+ * which on a corrupt block decodes to an arbitrary huge value
+ * and turns this into an out-of-bounds memset().
+ */
de->inode = 0;
- memset(&de->name_len, 0, ext4_rec_len_from_disk(de->rec_len,
- blocksize) -
- offsetof(struct ext4_dir_entry_2,
- name_len));
+ memset(&de->name_len, 0, rec_len -
+ offsetof(struct ext4_dir_entry_2, name_len));
map++;
to += rec_len;
@@ -1992,6 +2008,12 @@ static struct ext4_dir_entry_2 *do_split(handle_t *handle, struct inode *dir,
/* Fancy dance to stay within two buffers */
de2 = dx_move_dirents(dir, data1, data2, map + split, count - split,
blocksize);
+ if (IS_ERR(de2)) {
+ ext4_error_inode_block(dir, (*bh)->b_blocknr, 0,
+ "bad indexed directory entry");
+ err = PTR_ERR(de2);
+ goto out;
+ }
de = dx_pack_dirents(dir, data1, blocksize);
de->rec_len = ext4_rec_len_to_disk(data1 + (blocksize - csum_size) -
(char *) de,
--
2.51.0
^ permalink raw reply [flat|nested] 6+ messages in thread* Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
2026-09-28 21:54 [syzbot] [ext4?] KASAN: slab-use-after-free Write in do_split syzbot
` (2 preceding siblings ...)
2026-10-01 20:34 ` Forwarded: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents() syzbot
@ 2026-10-01 21:30 ` syzbot
3 siblings, 0 replies; 6+ messages in thread
From: syzbot @ 2026-10-01 21:30 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] ext4: don't trust on-disk rec_len in dx_move_dirents()
Author: adrianox@gmail.com
#syz test: upstream master
syzbot reported an out-of-bounds write from do_split() while a directory
is converted to an indexed one:
BUG: KASAN: slab-out-of-bounds in dx_move_dirents [inline]
BUG: KASAN: slab-out-of-bounds in do_split+0xf9c/0x1de0
Write of size 90458
dx_move_dirents() wipes the source entry using its on-disk rec_len.
That field can't be trusted: on a corrupt block it may be garbage
(0x6161 here) and ext4_rec_len_from_disk() turns it into a huge value,
so the memset() runs far past the block. The entry is already copied
using its own real length, so use that length for the wipe as well.
Closes: https://syzkaller.appspot.com/bug?extid=09bec78ee77613a3efdd
---
fs/ext4/namei.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index a6386c1d237f..71e9e7c9a7fd 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -1860,10 +1860,8 @@ dx_move_dirents(struct inode *dir, char *from, char *to,
/* wipe dir_entry excluding the rec_len field */
de->inode = 0;
- memset(&de->name_len, 0, ext4_rec_len_from_disk(de->rec_len,
- blocksize) -
- offsetof(struct ext4_dir_entry_2,
- name_len));
+ memset(&de->name_len, 0, rec_len -
+ offsetof(struct ext4_dir_entry_2, name_len));
map++;
to += rec_len;
--
2.51.0
^ permalink raw reply [flat|nested] 6+ messages in thread