mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 5.10/5.15] io_uring: avoid null-ptr-deref in io_arm_poll_handler
@ 2023-03-16 18:56 Fedor Pchelkin
  2023-03-16 18:58 ` Jens Axboe
  2023-03-16 19:04 ` Greg Kroah-Hartman
  0 siblings, 2 replies; 5+ messages in thread
From: Fedor Pchelkin @ 2023-03-16 18:56 UTC (permalink / raw)
  To: Jens Axboe, Greg Kroah-Hartman, stable
  Cc: Fedor Pchelkin, linux-kernel, Alexey Khoroshilov, lvc-project

No upstream commit exists for this commit.

The issue was introduced with backporting upstream commit c16bda37594f
("io_uring/poll: allow some retries for poll triggering spuriously").

Memory allocation can possibly fail causing invalid pointer be
dereferenced just before comparing it to NULL value.

Move the pointer check in proper place (upstream has the similar location
of the check). In case the request has REQ_F_POLLED flag up, apoll can't
be NULL so no need to check there.

Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Signed-off-by: Fedor Pchelkin <pchelkin@ispras.ru>
---
 io_uring/io_uring.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/io_uring/io_uring.c b/io_uring/io_uring.c
index 445afda927f4..fd799567fc23 100644
--- a/io_uring/io_uring.c
+++ b/io_uring/io_uring.c
@@ -5792,10 +5792,10 @@ static int io_arm_poll_handler(struct io_kiocb *req)
 		}
 	} else {
 		apoll = kmalloc(sizeof(*apoll), GFP_ATOMIC);
+		if (unlikely(!apoll))
+			return IO_APOLL_ABORTED;
 		apoll->poll.retries = APOLL_MAX_RETRY;
 	}
-	if (unlikely(!apoll))
-		return IO_APOLL_ABORTED;
 	apoll->double_poll = NULL;
 	req->apoll = apoll;
 	req->flags |= REQ_F_POLLED;
-- 
2.34.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2023-03-16 19:25 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-03-16 18:56 [PATCH 5.10/5.15] io_uring: avoid null-ptr-deref in io_arm_poll_handler Fedor Pchelkin
2023-03-16 18:58 ` Jens Axboe
2023-03-16 19:04 ` Greg Kroah-Hartman
2023-03-16 19:22   ` Fedor Pchelkin
2023-03-16 19:25     ` Jens Axboe

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®