From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f43.google.com (mail-ej1-f43.google.com [209.85.218.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CBA5133D4F0 for ; Wed, 12 Aug 2026 07:01:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786518063; cv=none; b=Un/krvj+Z85F+A7ihh346Dcw6CYl5738iR6y5mAtYTJXZ2Luggn0dZfxHfPvzUAcK9wh6/8BCccuwd7kkykIMQgzWKlF7U/FlnRskby5/YB1xVAk3f2IZjgBIsMpG912GnIx6yiZf8GEber+IxrI9ClEp7b6f6CE8CJseIEu9qg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786518063; c=relaxed/simple; bh=gj3FipAk0mkZ1G0uWUhFzsPLLcHh/3vI4CjUXtgNn60=; h=Message-ID:Date:MIME-Version:Subject:From:To:Cc:References: In-Reply-To:Content-Type; b=Ksn0EO8PIgEzwpZP4HGtmR3AKL5kAOuHYaQgqpIYHFMe2GKL9dXG4tqi81Zddo+9Wi2CuLM0lDQLHtp63OLmomwDfGptAsTUIsw7gUt5izgJrHOwxj3TUE6qQcUTyJ4uY2TxUUcVpax33uOGVN9GxOUxreTcMYtQbj5l7u+/jT0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=lSDc2+4D; arc=none smtp.client-ip=209.85.218.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="lSDc2+4D" Received: by mail-ej1-f43.google.com with SMTP id a640c23a62f3a-c1fbe461f59so99161566b.2 for ; Wed, 12 Aug 2026 00:01:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786518059; x=1787122859; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:content-language :references:cc:to:from:subject:user-agent:mime-version:date :message-id:from:to:cc:subject:date:message-id:reply-to:content-type; bh=8f1xvm/nWHthIx3tuw3JQX6WiPdj3gaDMF2QvCAcy3M=; b=lSDc2+4D/CytqsGIAPVkikMapr2jJL+7I7ewGrOzE6fU3FUnsYuBtFQWrz6Z4AsjXq PikjE7O5yc9E/EolqVRvdkktiYP9P/bhiKZ8+K6hyZHf+HWYAt0dR9sbgSxhpdQ2TXJV yeHwESDX8qh4RUC61U/c99ydvG5wQRWKoePHxHbKsg/AbhyQtEvZLlsEl9Ew1m/izPGA xgMifstia887l3sETqQs/UIw41WjVF+ofqq/4s/OKMass0jkBD8Vjd77ePLwOylxN3Xl BuB6FK5QCtqSND7iSDphtFYpDrEclGunAo/ReOmvS8v4cRyI/graDQ4QQjSLI2Hu42PA 9cTA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786518059; x=1787122859; h=content-transfer-encoding:content-type:in-reply-to:content-language :references:cc:to:from:subject:user-agent:mime-version:date :message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8f1xvm/nWHthIx3tuw3JQX6WiPdj3gaDMF2QvCAcy3M=; b=C2TNzFoM/mg3bPB6aAX3S3bxeHc1C0dg46yjqadUBYS2HDlC4dXL9TNJfsHJbNLEL+ PMnlOhpNHE2hfn2SnSna/Yb27y0BTq+CaqSG5PUSjM37efAARAjUP8eq9LrqkH6HNGLt 8yADU3kVhiTp7KNOEEwmemvfelflvZ3a6QnBb2Al0rmyLRe39AhgqLyjQ8xMqPvU2fc1 P4qcA5TIATvbdhltc2zLxxr/H/LVGyJmCUtEd5Rumwl0J4iPy5FzW7n01D/vY/z0rAeC bSbuU/pFjxeRtLm5pMRzZ3MoODAvy1Bn0CFvoWoFCweMMeHHuOnTrdUn5xGr5dWUPCu3 Rb4Q== X-Forwarded-Encrypted: i=1; AHgh+RrXMvgGnqVqoAIFTLGDRxMfUjcEXZ1xtTqF0FnD6Aw6oB4PReHYgvx/hSrREHxDPyWrK2rXl83nZVZv0gk=@vger.kernel.org X-Gm-Message-State: AOJu0YxChSXmnECuDC3+6AUHSP04tRM+0FqS1P4OluJz1DyH/4JU5Fh1 tEOwiFCl/1Agu87dPZ7ozu4QQqXvfhO1n8GvWSBxu6Gqc7yl6xSLShRD X-Gm-Gg: AR+sD10VJqjb7QMjZRhzfEubFDwO/5Y2m5B05/9aiGGK4C8QuiLO//2otkpwPOU6MYt zR4eSY6ba7alGT9klp4+mDBAj0eURwxsbz6xNp4jtWQx8VML70SdoDq1K5epQCovU+pJS9abFD+ kLfQ2Qp8wujTNXKEVzcZ0X6N7aDz6ZoWhwWDjgaAothBbFsvncXAWboPxS1SrdIeBWtpwDNzxoA Zh+UbPWlu6Js6hkmnFOuj+pW1E8njtjNk0lQfaaFNpAZGzYPDKjT9rWCJbg8UaGGCcgKSO7EzuX Vwr6zB/V58xe7OFimSdLS9G6fVU0Daj0yZQrv1/TkQTOVHotP/w7Okfa6udVbmWjHdKnkczLOMm LKD7eJtEamz6EPeaxF/Hb4AVzi2O7YnCCxhuXH+hYULG0VNcAa+GP4jEmk3BAL4W04tKuuJ1Lhl 5vk8wb31jowY0bsopEqJNrhWwhsHd5lKU5+q2SwZg9+R74sKFjyB6TCNBQpO43n+2Q5o4JpBzS+ t3ZF251XrJe2e0xWu2uCgsm6Ri6m/LhZ8gMQXHrqTAWTRBUoEMjHtUSd7h88K4= X-Received: by 2002:a17:907:3e91:b0:c1c:332b:74a1 with SMTP id a640c23a62f3a-c20f3079a68mr139534366b.28.1786518058692; Wed, 12 Aug 2026 00:00:58 -0700 (PDT) Received: from [192.168.178.24] (cgn-195-14-219-6.nc.de. [195.14.219.6]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d4e3f5sm4639567f8f.22.2026.08.12.00.00.57 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 12 Aug 2026 00:00:58 -0700 (PDT) Message-ID: Date: Wed, 12 Aug 2026 09:00:57 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 0/2] configfs: fix use-after-free of symlink target racing with rmdir From: Vasileios Almpanis To: Andreas Hindborg Cc: Breno Leitao , Al Viro , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, syzbot+6b16e3d085833cbf3e25@syzkaller.appspotmail.com References: <20260730093435.195441-1-vasilisalmpanis@gmail.com> Content-Language: en-US In-Reply-To: <20260730093435.195441-1-vasilisalmpanis@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 7/30/26 11:30 AM, Vasileios Almpanis wrote: > syzkaller reported a slab-use-after-free in config_item_get() when > symlink(2) races with rmdir(2) of the symlink target: > > BUG: KASAN: slab-use-after-free in config_item_get+0x26/0x90 > configfs_get_config_item fs/configfs/configfs_internal.h:127 [inline] > get_target fs/configfs/symlink.c:128 [inline] > configfs_symlink+0x4ab/0x1030 fs/configfs/symlink.c:185 > > configfs_symlink() resolves the target with no locks, with the idea > that a hashed dentry means a live config_item. configfs_rmdir() drops > the last reference to the item before the dentry gets unhashed by > d_delete() in vfs_rmdir(), so get_target() could take a reference on > an already freed item. > > Patch 2 fixes this by unhashing the dentry in configfs_remove_dir(), > before the item can be freed. Patch 1 fixes a second lifetime bug in > the same path that the earlier unhashing makes easy to hit: an item > reference does not pin the item's dentry, so create_link() must not > reach the target's configfs_dirent through ->ci_dentry. The patches > must be applied in this order. > > Tested with the syzkaller reproducer, which no longer triggers either > the KASAN report or the s_count warning. > > Vasileios Almpanis (2): > configfs: pin the symlink target's dirent instead of chasing > ->ci_dentry > configfs: unhash the dentry before dropping the item in rmdir > > fs/configfs/dir.c | 9 +++++++++ > fs/configfs/symlink.c | 24 ++++++++++++++++++++---- > 2 files changed, 29 insertions(+), 4 deletions(-) > > Hi everyone, Regarding this series, is there anything I could have done differently? Any suggestions or advice would be greatly appreciated. Thanks, Vasileios