mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 12:44:03 +02:00
md/md-llbitmap: prevent create failure bitmap UAF
llbitmap_create() publishes mddev->bitmap before reading the bitmap
superblock. This is needed because llbitmap_read_sb() can initialize a
new bitmap and flush it through helpers that use mddev->bitmap.
If llbitmap_read_sb() fails, the old cleanup dropped bitmap_info.mutex
and freed llbitmap before clearing mddev->bitmap. Readers such as
/proc/mdstat rely on bitmap_info.mutex to keep the bitmap pointer stable
while collecting bitmap stats, so they could observe the stale pointer
after the failed create path released the mutex.
Clear mddev->bitmap while still holding bitmap_info.mutex, then free the
failed llbitmap after dropping the mutex. This makes mutex-protected
readers see either a live bitmap or no bitmap.
Fixes: 5ab829f197 ("md/md-llbitmap: introduce new lockless bitmap")
Tested-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://patch.msgid.link/20260802195038.164272-9-yukuai@kernel.org
Signed-off-by: Yu Kuai <yukuai@fygo.io>
This commit is contained in:
parent
45102fc833
commit
2116c2f0a0
|
|
@ -1126,10 +1126,11 @@ static int llbitmap_create(struct mddev *mddev)
|
|||
mutex_lock(&mddev->bitmap_info.mutex);
|
||||
mddev->bitmap = llbitmap;
|
||||
ret = llbitmap_read_sb(llbitmap);
|
||||
if (ret)
|
||||
mddev->bitmap = NULL;
|
||||
mutex_unlock(&mddev->bitmap_info.mutex);
|
||||
if (ret) {
|
||||
kfree(llbitmap);
|
||||
mddev->bitmap = NULL;
|
||||
}
|
||||
|
||||
return ret;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user