mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Mike Christie <michael.christie@oracle.com>
To: Linfeng Sun <linfeng.sun.dev@gmail.com>,
	"Martin K . Petersen" <martin.petersen@oracle.com>,
	Alok Tiwari <alok.a.tiwari@oracle.com>
Cc: linux-scsi@vger.kernel.org, target-devel@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH] scsi: target: iscsi: Fix race in discovery auth updates
Date: Tue, 6 Oct 2026 19:24:06 -0500	[thread overview]
Message-ID: <c3b38eed-ce5c-4123-8d14-28e01eb24f6c@oracle.com> (raw)
In-Reply-To: <20260811124843.6817-1-linfeng.sun.dev@gmail.com>

On 8/11/26 7:48 AM, Linfeng Sun wrote:
> Separate configfs opens can concurrently update the discovery AuthMethod
> parameter. Both callers may free the same value in
> iscsi_update_param_value(), causing a double-free.
> 
> Protect the lookup and replacement with the discovery TPG access lock, as
> used by the other TPG configfs parameter updates.
> 
> I dont consider this a high-severity security bug, but for safety as a
> precaution, I can provide the reproducer PoC privately to the maintainers
> if needed.
> 
> [   53.935693] ==================================================================
> [   53.936125] BUG: KASAN: double-free in iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [   53.936725] Free of addr ffff888012e355b0 by task a.out/319
> [   53.937027]
> [   53.937120] CPU: 6 UID: 0 PID: 319 Comm: a.out Not tainted 7.2.0-rc7+ #3 PREEMPT(full)
> [   53.937130] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
> [   53.937136] Call Trace:
> [   53.937139]  <TASK>
> [   53.937142]  dump_stack_lvl+0xd0/0x110
> [   53.937151]  print_report+0xd1/0x630
> [   53.937161]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10
> [   53.937173]  ? kasan_complete_mode_report_info+0x6a/0x210
> [   53.937182]  ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [   53.937327]  kasan_report_invalid_free+0xa0/0xd0
> [   53.937337]  ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [   53.937484]  ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [   53.937632]  check_slab_allocation+0xee/0x120
> [   53.937641]  __kasan_slab_pre_free+0x24/0x50
> [   53.937650]  kfree+0x170/0x480
> [   53.937657]  ? __pfx_kstrtouint+0x10/0x10
> [   53.937665]  ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [   53.937813]  iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [   53.937959]  iscsi_disc_enforce_discovery_auth_store+0x18f/0x450 [iscsi_target_mod]
> [   53.938111]  ? __pfx_iscsi_disc_enforce_discovery_auth_store+0x10/0x10 [iscsi_target_mod]
> [   53.938263]  ? __kmalloc_cache_noprof+0x1be/0x460
> [   53.938272]  ? configfs_write_iter+0x3fe/0x560
> [   53.938284]  ? __pfx_iscsi_disc_enforce_discovery_auth_store+0x10/0x10 [iscsi_target_mod]
> [   53.938435]  configfs_write_iter+0x312/0x560
> [   53.938447]  ? __sanitizer_cov_trace_const_cmp4+0x16/0x30
> [   53.938458]  vfs_write+0x71c/0xe60
> [   53.938464]  ? __pfx_configfs_write_iter+0x10/0x10
> [   53.938477]  ? __pfx_vfs_write+0x10/0x10
> [   53.938484]  ? __pfx_mutex_lock+0x10/0x10
> [   53.938493]  ? fdget_pos+0x213/0x5d0
> [   53.938505]  ksys_write+0x154/0x290
> [   53.938512]  ? __pfx_ksys_write+0x10/0x10
> [   53.938519]  ? fpregs_assert_state_consistent+0xe1/0x160
> [   53.938532]  ? do_syscall_64+0x13f/0x640
> [   53.938539]  ? __sanitizer_cov_trace_cmp4+0x16/0x30
> [   53.938549]  __x64_sys_write+0x77/0xc0
> [   53.938555]  ? prandom_u32_state+0x13/0x180
> [   53.938567]  x64_sys_call+0x259/0x26e0
> [   53.938579]  do_syscall_64+0xf3/0x640
> [   53.938585]  ? do_syscall_64+0xa8/0x640
> [   53.938592]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
> [   53.938601] RIP: 0033:0x7e9dc22449ee
> [   53.938607] Code: 08 0f 85 f5 4b ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
> [   53.938615] RSP: 002b:00007e9dc19a4e08 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
> [   53.938623] RAX: ffffffffffffffda RBX: 00007e9dc19a56c0 RCX: 00007e9dc22449ee
> [   53.938628] RDX: 0000000000000002 RSI: 00005a09e22de04e RDI: 0000000000000004
> [   53.938633] RBP: 00007e9dc19a4e90 R08: 0000000000000000 R09: 0000000000000000
> [   53.938638] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000021
> [   53.938642] R13: 0000000000000000 R14: 00007ffcf2f464d0 R15: 00007e9dc11a5000
> [   53.938649]  </TASK>
> [   53.938652]
> [   53.953000] Allocated by task 308:
> [   53.953189]  kasan_save_stack+0x39/0x70
> [   53.953404]  kasan_save_track+0x14/0x40
> [   53.953617]  kasan_save_alloc_info+0x37/0x60
> [   53.953858]  __kasan_kmalloc+0xc3/0xd0
> [   53.954073]  __kmalloc_node_track_caller_noprof+0x24b/0x630
> [   53.954385]  kstrdup+0x62/0x110
> [   53.954567]  iscsi_update_param_value+0x4e/0x140 [iscsi_target_mod]
> [   53.955055]  iscsit_load_discovery_tpg+0x3fc/0x6e0 [iscsi_target_mod]
> [   53.955545]  0xffffffffa0479430
> [   53.955724]  do_one_initcall+0xd7/0x660
> [   53.955943]  do_init_module+0x306/0x940
> [   53.956165]  load_module+0x66c2/0x90f0
> [   53.956378]  init_module_from_file+0x192/0x1c0
> [   53.956626]  idempotent_init_module+0x274/0x8c0
> [   53.956883]  __x64_sys_finit_module+0xd3/0x170
> [   53.957134]  x64_sys_call+0x106d/0x26e0
> [   53.957354]  do_syscall_64+0xf3/0x640
> [   53.957562]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
> [   53.957851]
> [   53.957946] Freed by task 318:
> [   53.958122]  kasan_save_stack+0x39/0x70
> [   53.958342]  kasan_save_track+0x14/0x40
> [   53.958562]  kasan_save_free_info+0x3b/0x60
> [   53.958802]  __kasan_slab_free+0x6f/0xa0
> [   53.959034]  kfree+0x23c/0x480
> [   53.959210]  iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
> [   53.959678]  iscsi_disc_enforce_discovery_auth_store+0x18f/0x450 [iscsi_target_mod]
> [   53.960236]  configfs_write_iter+0x312/0x560
> [   53.960478]  vfs_write+0x71c/0xe60
> [   53.960669]  ksys_write+0x154/0x290
> [   53.960865]  __x64_sys_write+0x77/0xc0
> [   53.961075]  x64_sys_call+0x259/0x26e0
> [   53.961287]  do_syscall_64+0xf3/0x640
> [   53.961490]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
> 
> Fixes: e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1")
> Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com>

Reviewed-by: Mike Christie <michael.christie@oracle.com>

      parent reply	other threads:[~2026-10-07  0:24 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-11 12:48 Linfeng Sun
2026-08-26  4:36 ` Linfeng Sun
2026-10-07  0:24 ` Mike Christie [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=c3b38eed-ce5c-4123-8d14-28e01eb24f6c@oracle.com \
    --to=michael.christie@oracle.com \
    --cc=alok.a.tiwari@oracle.com \
    --cc=linfeng.sun.dev@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=martin.petersen@oracle.com \
    --cc=target-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®