From: Linfeng Sun <linfeng.sun.dev@gmail.com>
To: "Martin K . Petersen" <martin.petersen@oracle.com>,
Alok Tiwari <alok.a.tiwari@oracle.com>,
Mike Christie <michael.christie@oracle.com>
Cc: linux-scsi@vger.kernel.org, target-devel@vger.kernel.org,
linux-kernel@vger.kernel.org,
Linfeng Sun <linfeng.sun.dev@gmail.com>
Subject: [PATCH] scsi: target: iscsi: Fix race in discovery auth updates
Date: Tue, 11 Aug 2026 20:48:43 +0800 [thread overview]
Message-ID: <20260811124843.6817-1-linfeng.sun.dev@gmail.com> (raw)
Separate configfs opens can concurrently update the discovery AuthMethod
parameter. Both callers may free the same value in
iscsi_update_param_value(), causing a double-free.
Protect the lookup and replacement with the discovery TPG access lock, as
used by the other TPG configfs parameter updates.
I dont consider this a high-severity security bug, but for safety as a
precaution, I can provide the reproducer PoC privately to the maintainers
if needed.
[ 53.935693] ==================================================================
[ 53.936125] BUG: KASAN: double-free in iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
[ 53.936725] Free of addr ffff888012e355b0 by task a.out/319
[ 53.937027]
[ 53.937120] CPU: 6 UID: 0 PID: 319 Comm: a.out Not tainted 7.2.0-rc7+ #3 PREEMPT(full)
[ 53.937130] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 53.937136] Call Trace:
[ 53.937139] <TASK>
[ 53.937142] dump_stack_lvl+0xd0/0x110
[ 53.937151] print_report+0xd1/0x630
[ 53.937161] ? __pfx__raw_spin_lock_irqsave+0x10/0x10
[ 53.937173] ? kasan_complete_mode_report_info+0x6a/0x210
[ 53.937182] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
[ 53.937327] kasan_report_invalid_free+0xa0/0xd0
[ 53.937337] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
[ 53.937484] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
[ 53.937632] check_slab_allocation+0xee/0x120
[ 53.937641] __kasan_slab_pre_free+0x24/0x50
[ 53.937650] kfree+0x170/0x480
[ 53.937657] ? __pfx_kstrtouint+0x10/0x10
[ 53.937665] ? iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
[ 53.937813] iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
[ 53.937959] iscsi_disc_enforce_discovery_auth_store+0x18f/0x450 [iscsi_target_mod]
[ 53.938111] ? __pfx_iscsi_disc_enforce_discovery_auth_store+0x10/0x10 [iscsi_target_mod]
[ 53.938263] ? __kmalloc_cache_noprof+0x1be/0x460
[ 53.938272] ? configfs_write_iter+0x3fe/0x560
[ 53.938284] ? __pfx_iscsi_disc_enforce_discovery_auth_store+0x10/0x10 [iscsi_target_mod]
[ 53.938435] configfs_write_iter+0x312/0x560
[ 53.938447] ? __sanitizer_cov_trace_const_cmp4+0x16/0x30
[ 53.938458] vfs_write+0x71c/0xe60
[ 53.938464] ? __pfx_configfs_write_iter+0x10/0x10
[ 53.938477] ? __pfx_vfs_write+0x10/0x10
[ 53.938484] ? __pfx_mutex_lock+0x10/0x10
[ 53.938493] ? fdget_pos+0x213/0x5d0
[ 53.938505] ksys_write+0x154/0x290
[ 53.938512] ? __pfx_ksys_write+0x10/0x10
[ 53.938519] ? fpregs_assert_state_consistent+0xe1/0x160
[ 53.938532] ? do_syscall_64+0x13f/0x640
[ 53.938539] ? __sanitizer_cov_trace_cmp4+0x16/0x30
[ 53.938549] __x64_sys_write+0x77/0xc0
[ 53.938555] ? prandom_u32_state+0x13/0x180
[ 53.938567] x64_sys_call+0x259/0x26e0
[ 53.938579] do_syscall_64+0xf3/0x640
[ 53.938585] ? do_syscall_64+0xa8/0x640
[ 53.938592] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 53.938601] RIP: 0033:0x7e9dc22449ee
[ 53.938607] Code: 08 0f 85 f5 4b ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
[ 53.938615] RSP: 002b:00007e9dc19a4e08 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
[ 53.938623] RAX: ffffffffffffffda RBX: 00007e9dc19a56c0 RCX: 00007e9dc22449ee
[ 53.938628] RDX: 0000000000000002 RSI: 00005a09e22de04e RDI: 0000000000000004
[ 53.938633] RBP: 00007e9dc19a4e90 R08: 0000000000000000 R09: 0000000000000000
[ 53.938638] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000021
[ 53.938642] R13: 0000000000000000 R14: 00007ffcf2f464d0 R15: 00007e9dc11a5000
[ 53.938649] </TASK>
[ 53.938652]
[ 53.953000] Allocated by task 308:
[ 53.953189] kasan_save_stack+0x39/0x70
[ 53.953404] kasan_save_track+0x14/0x40
[ 53.953617] kasan_save_alloc_info+0x37/0x60
[ 53.953858] __kasan_kmalloc+0xc3/0xd0
[ 53.954073] __kmalloc_node_track_caller_noprof+0x24b/0x630
[ 53.954385] kstrdup+0x62/0x110
[ 53.954567] iscsi_update_param_value+0x4e/0x140 [iscsi_target_mod]
[ 53.955055] iscsit_load_discovery_tpg+0x3fc/0x6e0 [iscsi_target_mod]
[ 53.955545] 0xffffffffa0479430
[ 53.955724] do_one_initcall+0xd7/0x660
[ 53.955943] do_init_module+0x306/0x940
[ 53.956165] load_module+0x66c2/0x90f0
[ 53.956378] init_module_from_file+0x192/0x1c0
[ 53.956626] idempotent_init_module+0x274/0x8c0
[ 53.956883] __x64_sys_finit_module+0xd3/0x170
[ 53.957134] x64_sys_call+0x106d/0x26e0
[ 53.957354] do_syscall_64+0xf3/0x640
[ 53.957562] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 53.957851]
[ 53.957946] Freed by task 318:
[ 53.958122] kasan_save_stack+0x39/0x70
[ 53.958342] kasan_save_track+0x14/0x40
[ 53.958562] kasan_save_free_info+0x3b/0x60
[ 53.958802] __kasan_slab_free+0x6f/0xa0
[ 53.959034] kfree+0x23c/0x480
[ 53.959210] iscsi_update_param_value+0x41/0x140 [iscsi_target_mod]
[ 53.959678] iscsi_disc_enforce_discovery_auth_store+0x18f/0x450 [iscsi_target_mod]
[ 53.960236] configfs_write_iter+0x312/0x560
[ 53.960478] vfs_write+0x71c/0xe60
[ 53.960669] ksys_write+0x154/0x290
[ 53.960865] __x64_sys_write+0x77/0xc0
[ 53.961075] x64_sys_call+0x259/0x26e0
[ 53.961287] do_syscall_64+0xf3/0x640
[ 53.961490] entry_SYSCALL_64_after_hwframe+0x76/0x7e
Fixes: e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1")
Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com>
---
drivers/target/iscsi/iscsi_target_configfs.c | 26 ++++++++++++++------
1 file changed, 19 insertions(+), 7 deletions(-)
diff --git a/drivers/target/iscsi/iscsi_target_configfs.c b/drivers/target/iscsi/iscsi_target_configfs.c
index 704ec94383c3..e1aa0af52c65 100644
--- a/drivers/target/iscsi/iscsi_target_configfs.c
+++ b/drivers/target/iscsi/iscsi_target_configfs.c
@@ -1306,17 +1306,24 @@ static ssize_t iscsi_disc_enforce_discovery_auth_store(struct config_item *item,
return -EINVAL;
}
+ if (iscsit_get_tpg(discovery_tpg) < 0)
+ return -EINVAL;
+
param = iscsi_find_param_from_key(AUTHMETHOD,
discovery_tpg->param_list);
- if (!param)
- return -EINVAL;
+ if (!param) {
+ err = -EINVAL;
+ goto out;
+ }
if (op) {
/*
* Reset the AuthMethod key to CHAP.
*/
- if (iscsi_update_param_value(param, CHAP) < 0)
- return -EINVAL;
+ if (iscsi_update_param_value(param, CHAP) < 0) {
+ err = -EINVAL;
+ goto out;
+ }
discovery_tpg->tpg_attrib.authentication = 1;
iscsit_global->discovery_acl.node_auth.enforce_discovery_auth = 1;
@@ -1327,8 +1334,10 @@ static ssize_t iscsi_disc_enforce_discovery_auth_store(struct config_item *item,
/*
* Reset the AuthMethod key to CHAP,None
*/
- if (iscsi_update_param_value(param, "CHAP,None") < 0)
- return -EINVAL;
+ if (iscsi_update_param_value(param, "CHAP,None") < 0) {
+ err = -EINVAL;
+ goto out;
+ }
discovery_tpg->tpg_attrib.authentication = 0;
iscsit_global->discovery_acl.node_auth.enforce_discovery_auth = 0;
@@ -1337,7 +1346,10 @@ static ssize_t iscsi_disc_enforce_discovery_auth_store(struct config_item *item,
" Discovery TPG\n");
}
- return count;
+ err = count;
+out:
+ iscsit_put_tpg(discovery_tpg);
+ return err;
}
CONFIGFS_ATTR(iscsi_disc_, enforce_discovery_auth);
--
2.55.0
reply other threads:[~2026-08-11 12:49 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260811124843.6817-1-linfeng.sun.dev@gmail.com \
--to=linfeng.sun.dev@gmail.com \
--cc=alok.a.tiwari@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=michael.christie@oracle.com \
--cc=target-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.