From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EC208279798 for ; Tue, 11 Aug 2026 12:53:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786452800; cv=none; b=JXA3m+fWy4ZSxi3OaPcWMOI5XcsHhsc4AaxhDmNjZ/lci0i1bPcmu0s2BysfUn5V6nffyvNK3KqwQnmkDY5bwUZdgNJOCPS1cWzRdLGAcMjWeNPgjE1MzQnzizWsAzKIdhAdt8qXB3iGVh88p8xEd7fGSPVNJGnXxqBfz1hpjzQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786452800; c=relaxed/simple; bh=Z2NF1lSZcfA/Ug7GpqM/dxNLGs2qoe++8fT7i6sF3UI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fFR+IyfWFOccbyTOpxUxua9LKNklAmASEPv1i9EUxAb5a3eTzCZnmVkU4ymvPwE2yBFM1UJoXkNJ7vtNm8lidzMq9ljxIWqrBap6wxuNfPiKKFp3nK/bmINK/bQmW992L/Uk5OAxqn6GS/Rf/QWJvjbQ5/fdnQ8HiX5VcUVQpZE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Pu4p5dwR; arc=none smtp.client-ip=209.85.216.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Pu4p5dwR" Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-38dfe7eb825so2533200a91.0 for ; Tue, 11 Aug 2026 05:53:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786452798; x=1787057598; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=znrTAOQkIkog0es1Yg/9vX2LmYDGtr+g7VxATtgtPyg=; b=Pu4p5dwRU04YXf/4bGhPnXzbWz8LOpDiJ/kQcmZu0AAKAtoojnbSNd7uzP26nzGA6L bXwjYl0yUd/rMQ0KrTqZYOCW+sMExWD+F5Yf9FOHUzlAuCR6sFULjpH1z8a5GthQa2hR Inu8wRwhHeDQR+45uP9KSMCBmKbNNgvDmcgHWjFOlP1jLd8UnKSOsOC7l4RQS+ulkuDB v4hDaewZyh0ib/+PRmI3mfAISafk5VcQ60v4EXexssRMMxUetxOASdgahhCjQA/utEFH x2xje+puTvoNuXKbCWy7WiildohJAXXl3KMxBoxmheCtjDHtMdDj5X1FSyfipxYVvfWJ hYDQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786452798; x=1787057598; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=znrTAOQkIkog0es1Yg/9vX2LmYDGtr+g7VxATtgtPyg=; b=fUHwjmlThcgt1whr81LjV2s09eVwqP68SpIsNEOiBZSBaX2vvMmJoPgdSPevuTZCWE fWOcMoITpzYRnyhPk+NHMQ7y4P5x7t6KTHr7Gz7/SkSP2yKwXvxHQTq4HIHytYztvpUN GME4j6FYy01tzVl1KOgFazWmWurUTY5TcBQX3dFQr9YWPaWPtNw8NvoexvZ5I4gScJAK vv2rkYQTifFtt0D0RQ3CwwfMPAzI7zYVrDcKoVLH1hGYXmRDnmVR6AglgsVQALBtZx2M dobaWmIjcI0uDVldiFZj3Ied2czBPiReydcbc9SfwnameRwux+RPwjKD8I6IWh3b/SYq tn9Q== X-Forwarded-Encrypted: i=1; AHgh+RrtpR62VZT60OwkedFYwyx4yRenZqUu1yZSIcmD1jOtSeBye4+ZFJjZLhZKotnOfNkmPNGFzXvR+CdkHxI=@vger.kernel.org X-Gm-Message-State: AOJu0YzOUBvQMb09S9PeSopwfpgVwQ/3/bbw439XKsaxLsyO725nzStv qVvOtqRoEVB5vdArqKhl0bGzzvh0B+X4Zv8GtQEPx7I1VsszjkC3BWucASEsmCOT X-Gm-Gg: AR+sD12AM2p++6+LEM2cJtk8whM4yvMyMSbmt7KU4wS+Az2nPLrxZVgfpjDAwYVSBlA l0nf1QQ0NfxgBnKdprRkueABCSwB1JTZVVjxF0bDef7r96HNGvt99nD18QBS8uEx9tqWF72y0/x 9Ew01+7U5CFQ+APYaObIO4LMfPUc5iI0OSDOMnt07FvRMMiQS2O23cx/YQrHWdoy31Iub8EGqjJ Gbf03gbA1XO2594HFGAjHsY2Xub27gRjXWt6PGXjOnlfg3mkPCP9b6HJJAD3F+8a5peV+Jquzbz zhzForhW0KV8GYGPHy5zA7qxqn8nBg19FVBAEpyLqxjOaBGNV9CT0lh+AcYeZXdY6BLt9TLQXZz V8UG3fNBUYuirpiboy0S8aO0mzQrcganV5twrvfMqwGQQpfJIXtRRG9bcLdp2cWweKC0xu6l28d G5pM+aoWhKEgOUMWtMz3Cdss/k1AXGRQbjWdi7hxlhJLE2owzSwiJCeLpp X-Received: by 2002:a17:90b:39cb:b0:38e:5ab7:ce9b with SMTP id 98e67ed59e1d1-392ec786ca1mr3147819a91.21.1786452798037; Tue, 11 Aug 2026 05:53:18 -0700 (PDT) Received: from ubuntu.. ([122.43.203.5]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-392d5195a4dsm4127732a91.4.2026.08.11.05.53.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 05:53:17 -0700 (PDT) From: Rihyeon Kim To: kbusch@kernel.org Cc: hch@lst.de, sagi@grimberg.me, axboe@kernel.dk, justin.tee@broadcom.com, nareshgottumukkala83@gmail.com, paul.ely@broadcom.com, kch@nvidia.com, linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH] nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails Date: Tue, 11 Aug 2026 21:53:10 +0900 Message-ID: <20260811125310.165487-1-rihyeon8648@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <6a7a83ac.01d0871a.3a0d52.00bb.GAE@google.com> References: <6a7a83ac.01d0871a.3a0d52.00bb.GAE@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit nvmf_create_ctrl() frees opts when ->create_ctrl() returns an error, so a transport must not free it on its own error paths. nvme_fc_ctrl_free() therefore only calls nvmf_free_options() while ctrl->ctrl.opts is still set, and nvme_fc_init_ctrl() clears that pointer before its last put. It only does so on the fail_ctrl: path, though. When nvme_add_ctrl() fails, nvme_fc_init_ctrl() jumps to out_put_ctrl: instead, so nvme_fc_ctrl_free() still sees ctrl->ctrl.opts set and frees opts, and nvmf_create_ctrl() frees it again. Reproduced with nvme-fcloop and failslab by failing the kvasprintf() in dev_set_name(), called from nvme_add_ctrl(): BUG: KASAN: slab-use-after-free in nvmf_free_options+0x30/0x190 nvmf_free_options+0x30/0x190 drivers/nvme/host/fabrics.c:1284 nvmf_create_ctrl drivers/nvme/host/fabrics.c:1374 [inline] Freed by task 5534: nvme_fc_ctrl_free drivers/nvme/host/fc.c:2374 [inline] nvme_fc_init_ctrl+0xe17/0x1450 drivers/nvme/host/fc.c:3605 Without KASAN opts is simply freed twice. nvme-tcp and nvme-rdma reach the same error path, but their free_ctrl only frees opts once the controller is on the global list, so they are not affected. Clear ctrl->ctrl.opts on the out_put_ctrl: path as well. The same injection then returns -EIO without a report. Fixes: 1a9e218195a5 ("nvme: split device add from initialization") Cc: stable@vger.kernel.org Reported-by: syzbot+f58e57380a6083c4041d@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=f58e57380a6083c4041d Assisted-by: Claude:claude-opus-5 Signed-off-by: Rihyeon Kim --- drivers/nvme/host/fc.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/nvme/host/fc.c b/drivers/nvme/host/fc.c index 04363b9c4489..e4d0eeccd846 100644 --- a/drivers/nvme/host/fc.c +++ b/drivers/nvme/host/fc.c @@ -3601,6 +3601,9 @@ nvme_fc_init_ctrl(struct device *dev, struct nvmf_ctrl_options *opts, nvme_uninit_ctrl(&ctrl->ctrl); out_put_ctrl: + /* nvme_add_ctrl() failures skip the clear in fail_ctrl: above */ + ctrl->ctrl.opts = NULL; + /* Remove core ctrl ref. */ nvme_put_ctrl(&ctrl->ctrl); base-commit: 0ce37745d4bfbc493f718169c3974898ffec8ee7 -- 2.43.0