From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from arkamax.eu (128-116-240-228.dyn.eolo.it [128.116.240.228]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2A096347C6 for ; Thu, 6 Aug 2026 12:24:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=128.116.240.228 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786019072; cv=none; b=NjkKXYMWNKsN3JC7F4aC4fXfB5fnNT8TwkXHqv3nUpO+m4EbA8BDHPQ6oc9sJg14L2SCpmzEVaXgBZ/AIjmvpmXKOXesudt1yjkunahccs5liep3vcEO2MsXyw5zmvDIPXHiM28ZUNcyG7BzQx6cKV0vUQgPY2ihapGwgEKE6Iw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786019072; c=relaxed/simple; bh=XXRyQX0fnP4m5eSqIAWzgNY40FmSTS4FHVT+kO2xicw=; h=Mime-Version:Content-Type:Date:Message-Id:Subject:From:To:Cc: References:In-Reply-To; b=YC7TwygzBDmdz19q+gPHKAQ89Gr1tePGz8r5mRXs9Z3hcC/e93DEAuqMbBnTNlymGgJWHFg2FjItCYmTu7R5EJ0uEKvqrj3brtfGJw7Z3ZN/4ItS9geUQWbE3r28xBpwfFq0kS+0xP1mkLuTZfRuDoJr6v5zCK3cJnOOF+0+aSw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=arkamax.eu; spf=pass smtp.mailfrom=arkamax.eu; dkim=pass (2048-bit key) header.d=arkamax.eu header.i=@arkamax.eu header.b=cCXgps5M; arc=none smtp.client-ip=128.116.240.228 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=arkamax.eu Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arkamax.eu Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=arkamax.eu header.i=@arkamax.eu header.b="cCXgps5M" DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; s=mail1; bh=XXRyQX0fnP4m5e SqIAWzgNY40FmSTS4FHVT+kO2xicw=; h=in-reply-to:references:cc:to:from: subject:date; d=arkamax.eu; b=cCXgps5MzlA+mXrNiNkkceQVKfvtx0N3BfiWeqYc GYa4NqKuNTqNIvraq9q1V9M3ybWWEiAldskgMs5aj8TZu2eIX+gYb42v81bcfdjqIRcCON 6QJGZYlV70wDREghthjbvJXgT+FAaSm77Rjzcb6ZFT4y9jbbFj2LGNxTZf/PgiAAGqnIUQ CFtBaaZem36paPp98X0bt4F2hcX2X3xJybMm9d2xAKJqw4L6L45b2vO20YUVFTQUlIs4/C zp69weaC9s4YQAMjsekVVd9CK787VukSTntZ/SW0Dq0jB+kQLCGqxM8imBGTDL0dcgm+eZ IWGRK7EmueqTsD/4Z7+IsA== Received: from localhost (128-116-240-228.dyn.eolo.it [128.116.240.228]) by arkamax.eu (OpenSMTPD) with ESMTPSA id 65e027f9 (TLSv1.3:TLS_AES_256_GCM_SHA384:256:NO); Thu, 6 Aug 2026 14:24:20 +0200 (CEST) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Thu, 06 Aug 2026 14:24:19 +0200 Message-Id: Subject: Re: [PATCH] nvmet-fc: fix invalid free in LS IOD error path From: "Maurizio Lombardi" To: "Jiang HongHui" , "Justin Tee" , "Naresh Gottumukkala" , "Paul Ely" Cc: "Christoph Hellwig" , "Sagi Grimberg" , "Chaitanya Kulkarni" , , X-Mailer: aerc 0.21.0 References: <20260729110206.207755-1-jiang_hh2019@163.com> In-Reply-To: <20260729110206.207755-1-jiang_hh2019@163.com> On Wed Jul 29, 2026 at 1:02 PM CEST, Jiang HongHui wrote: > nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD > array. If an rqstbuf allocation or response buffer DMA mapping fails, > the unwind loop decrements iod past the start of the array. The final > kfree(iod) therefore frees an address before the allocated object. > > This can be reproduced with nvme-fcloop and failslab by setting > fail-nth to 6 before creating a target port. KASAN reports: > > BUG: KASAN: invalid-free in nvmet_fc_register_targetport > Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552 > > Free the original allocation base stored in tgtport->iod instead. With > this fix applied, the same sysfs write with fail-nth=3D6 returns -ENOMEM > without any KASAN report. > > Fixes: c53432030d86 ("nvme-fabrics: Add target support for FC transport") > Cc: stable@vger.kernel.org > Assisted-by: Codex:gpt-5 > Signed-off-by: Jiang HongHui > --- > Tested on v7.2-rc5 with CONFIG_NVME_TARGET_FCLOOP=3Dm, CONFIG_KASAN=3Dy, > CONFIG_FAULT_INJECTION=3Dy and CONFIG_FAILSLAB=3Dy. > > Before the fix, faddr2line resolved the fail-nth=3D6 injection to the > rqstbuf kzalloc() at drivers/nvme/target/fc.c:542, and KASAN reported > an invalid free. After the fix, the same injection resolved to the same > allocation, the sysfs write returned -ENOMEM, fail-nth read back as 0, > and dmesg contained no KASAN, invalid-free, BAD_PAGE or Oops reports. > > drivers/nvme/target/fc.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/nvme/target/fc.c b/drivers/nvme/target/fc.c > index d16170755..1b557775e 100644 > --- a/drivers/nvme/target/fc.c > +++ b/drivers/nvme/target/fc.c > @@ -566,7 +566,7 @@ nvmet_fc_alloc_ls_iodlist(struct nvmet_fc_tgtport *tg= tport) > list_del(&iod->ls_rcv_list); > } > =20 > - kfree(iod); > + kfree(tgtport->iod); > =20 > return -EFAULT; > } > > base-commit: f5098b6bae761e346ebcd9da7f95622c04733cff Reviewed-by: Maurizio Lombardi