From: Mike Christie <michael.christie@oracle.com>
To: Linfeng Sun <linfeng.sun.dev@gmail.com>,
"Martin K . Petersen" <martin.petersen@oracle.com>,
Alok Tiwari <alok.a.tiwari@oracle.com>
Cc: linux-scsi@vger.kernel.org, target-devel@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] scsi: target: iscsi: Fix race in discovery auth updates
Date: Tue, 6 Oct 2026 19:24:06 -0500 [thread overview]
Message-ID: <c3b38eed-ce5c-4123-8d14-28e01eb24f6c@oracle.com> (raw)
In-Reply-To: <20260811124843.6817-1-linfeng.sun.dev@gmail.com>
On 8/11/26 7:48 AM, Linfeng Sun wrote:
> Separate configfs opens can concurrently update the discovery AuthMethod
> parameter. Both callers may free the same value in
> iscsi_update_param_value(), causing a double-free.
>
> Protect the lookup and replacement with the discovery TPG access lock, as
> used by the other TPG configfs parameter updates.
>
> I dont consider this a high-severity security bug, but for safety as a
> precaution, I can provide the reproducer PoC privately to the maintainers
> if needed.
>
> [ 53.935693] ==================================================================
> [ 53.936125] BUG: KASAN: double-free in iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [ 53.936725] Free of addr ffff888012e355b0 by task a.out/319
> [ 53.937027]
> [ 53.937120] CPU: 6 UID: 0 PID: 319 Comm: a.out Not tainted 7.2.0-rc7+ #3 PREEMPT(full)
> [ 53.937130] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
> [ 53.937136] Call Trace:
> [ 53.937139] <TASK>
> [ 53.937142] dump_stack_lvl+0xd0/0x110
> [ 53.937151] print_report+0xd1/0x630
> [ 53.937161] ? __pfx__raw_spin_lock_irqsave+0x10/0x10
> [ 53.937173] ? kasan_complete_mode_report_info+0x6a/0x210
> [ 53.937182] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [ 53.937327] kasan_report_invalid_free+0xa0/0xd0
> [ 53.937337] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [ 53.937484] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [ 53.937632] check_slab_allocation+0xee/0x120
> [ 53.937641] __kasan_slab_pre_free+0x24/0x50
> [ 53.937650] kfree+0x170/0x480
> [ 53.937657] ? __pfx_kstrtouint+0x10/0x10
> [ 53.937665] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [ 53.937813] iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [ 53.937959] iscsi_disc_enforce_discovery_auth_store+0x18f/0x450 [iscsi_target_mod]
> [ 53.938111] ? __pfx_iscsi_disc_enforce_discovery_auth_store+0x10/0x10 [iscsi_target_mod]
> [ 53.938263] ? __kmalloc_cache_noprof+0x1be/0x460
> [ 53.938272] ? configfs_write_iter+0x3fe/0x560
> [ 53.938284] ? __pfx_iscsi_disc_enforce_discovery_auth_store+0x10/0x10 [iscsi_target_mod]
> [ 53.938435] configfs_write_iter+0x312/0x560
> [ 53.938447] ? __sanitizer_cov_trace_const_cmp4+0x16/0x30
> [ 53.938458] vfs_write+0x71c/0xe60
> [ 53.938464] ? __pfx_configfs_write_iter+0x10/0x10
> [ 53.938477] ? __pfx_vfs_write+0x10/0x10
> [ 53.938484] ? __pfx_mutex_lock+0x10/0x10
> [ 53.938493] ? fdget_pos+0x213/0x5d0
> [ 53.938505] ksys_write+0x154/0x290
> [ 53.938512] ? __pfx_ksys_write+0x10/0x10
> [ 53.938519] ? fpregs_assert_state_consistent+0xe1/0x160
> [ 53.938532] ? do_syscall_64+0x13f/0x640
> [ 53.938539] ? __sanitizer_cov_trace_cmp4+0x16/0x30
> [ 53.938549] __x64_sys_write+0x77/0xc0
> [ 53.938555] ? prandom_u32_state+0x13/0x180
> [ 53.938567] x64_sys_call+0x259/0x26e0
> [ 53.938579] do_syscall_64+0xf3/0x640
> [ 53.938585] ? do_syscall_64+0xa8/0x640
> [ 53.938592] entry_SYSCALL_64_after_hwframe+0x76/0x7e
> [ 53.938601] RIP: 0033:0x7e9dc22449ee
> [ 53.938607] Code: 08 0f 85 f5 4b ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
> [ 53.938615] RSP: 002b:00007e9dc19a4e08 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
> [ 53.938623] RAX: ffffffffffffffda RBX: 00007e9dc19a56c0 RCX: 00007e9dc22449ee
> [ 53.938628] RDX: 0000000000000002 RSI: 00005a09e22de04e RDI: 0000000000000004
> [ 53.938633] RBP: 00007e9dc19a4e90 R08: 0000000000000000 R09: 0000000000000000
> [ 53.938638] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000021
> [ 53.938642] R13: 0000000000000000 R14: 00007ffcf2f464d0 R15: 00007e9dc11a5000
> [ 53.938649] </TASK>
> [ 53.938652]
> [ 53.953000] Allocated by task 308:
> [ 53.953189] kasan_save_stack+0x39/0x70
> [ 53.953404] kasan_save_track+0x14/0x40
> [ 53.953617] kasan_save_alloc_info+0x37/0x60
> [ 53.953858] __kasan_kmalloc+0xc3/0xd0
> [ 53.954073] __kmalloc_node_track_caller_noprof+0x24b/0x630
> [ 53.954385] kstrdup+0x62/0x110
> [ 53.954567] iscsi_update_param_value+0x4e/0x140 [iscsi_target_mod]
> [ 53.955055] iscsit_load_discovery_tpg+0x3fc/0x6e0 [iscsi_target_mod]
> [ 53.955545] 0xffffffffa0479430
> [ 53.955724] do_one_initcall+0xd7/0x660
> [ 53.955943] do_init_module+0x306/0x940
> [ 53.956165] load_module+0x66c2/0x90f0
> [ 53.956378] init_module_from_file+0x192/0x1c0
> [ 53.956626] idempotent_init_module+0x274/0x8c0
> [ 53.956883] __x64_sys_finit_module+0xd3/0x170
> [ 53.957134] x64_sys_call+0x106d/0x26e0
> [ 53.957354] do_syscall_64+0xf3/0x640
> [ 53.957562] entry_SYSCALL_64_after_hwframe+0x76/0x7e
> [ 53.957851]
> [ 53.957946] Freed by task 318:
> [ 53.958122] kasan_save_stack+0x39/0x70
> [ 53.958342] kasan_save_track+0x14/0x40
> [ 53.958562] kasan_save_free_info+0x3b/0x60
> [ 53.958802] __kasan_slab_free+0x6f/0xa0
> [ 53.959034] kfree+0x23c/0x480
> [ 53.959210] iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [ 53.959678] iscsi_disc_enforce_discovery_auth_store+0x18f/0x450 [iscsi_target_mod]
> [ 53.960236] configfs_write_iter+0x312/0x560
> [ 53.960478] vfs_write+0x71c/0xe60
> [ 53.960669] ksys_write+0x154/0x290
> [ 53.960865] __x64_sys_write+0x77/0xc0
> [ 53.961075] x64_sys_call+0x259/0x26e0
> [ 53.961287] do_syscall_64+0xf3/0x640
> [ 53.961490] entry_SYSCALL_64_after_hwframe+0x76/0x7e
>
> Fixes: e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1")
> Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com>
Reviewed-by: Mike Christie <michael.christie@oracle.com>
prev parent reply other threads:[~2026-10-07 0:24 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 12:48 Linfeng Sun
2026-08-26 4:36 ` Linfeng Sun
2026-10-07 0:24 ` Mike Christie [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c3b38eed-ce5c-4123-8d14-28e01eb24f6c@oracle.com \
--to=michael.christie@oracle.com \
--cc=alok.a.tiwari@oracle.com \
--cc=linfeng.sun.dev@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=target-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®