From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f52.google.com (mail-pj1-f52.google.com [209.85.216.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4095F2C1586 for ; Wed, 12 Aug 2026 12:25:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786537511; cv=none; b=WofhZGxhINvnSLJYo7qrdLI5n/5ZhukRKgjMVt0bMZLbs7IEMZ3PM2qiCc34KXMbJE52xGU1ZjfWsv0vZNaKZIU12f6gLnYb/BPkCMizgCsfJ1tNEQ7qvX4rmApmYlMR6bt80GP+FGQRj2Z06fLjjMYIdNEbiDSylm0NjQAubBw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786537511; c=relaxed/simple; bh=m8EMvCCK128RB/wkI3ycm2IUkmCyHXuU7mybLnkZoFA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=QXC8Tw0lHNWyXc6ldgit2MuzQwYwcwgnwcIIXbUd70OjYcp5ypvbl91YST3yeC0tyVrU/YlT0iirqtdykGlqLbusuGExu3UUtBX+yoHgFnQtTqQR+pN7inSbIiD8zAz9BP0GvPInYmHN+e9HtbqodXQc/PpAeclHU6vMgacVyLQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=WPTpQ7Ye; arc=none smtp.client-ip=209.85.216.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="WPTpQ7Ye" Received: by mail-pj1-f52.google.com with SMTP id 98e67ed59e1d1-38511175ad3so768442a91.2 for ; Wed, 12 Aug 2026 05:25:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786537509; x=1787142309; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=LsN70vJV1KtQSRtRhVm0IvWc/lzlWCqm6SEoGjkKJBs=; b=WPTpQ7YeQEMDCTXNqOnaHjXSqMH2y8S93LSFVxqErQ/JuDqHnDAH5AmBXx7KeBnBWt 2sqPWl/koZIi3KQQBV4GCn0TGr20Spm/veVML5Rg6ye94uYke+b2XEs8431Gu3180TJb zeWAUnrYqMixdKDu1LL3rpiRtZHadcXmSp1bf6rdZhlMaRJwUkO5eIGzGnJO3h9db6fp eoFypgqXFNM0YW6ezmAKly9+Cl7+inZciAfV46iqpx8YPeFXn1TLRI8as/fyyX+ZgTyD bMUISEWNNKqMzIcsitAYDMB6Pgw0rRhh2IIUaOj9UI4KJi1m/05RQTsXZY5YNPfDWyYu ng/w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786537509; x=1787142309; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=LsN70vJV1KtQSRtRhVm0IvWc/lzlWCqm6SEoGjkKJBs=; b=OnJN6VLCztlPBx/wiYCDKSQ6zvNnxHAPoeMZmfRymk2jWWUZuvPgmkES/vP7wf5qHh DZQWQMYDFioDd3AuI6BpeJhkAf2h+/35dup06MnQTXG2M/c0AyLH+wu0u5mL6fozMQVG 9B9PLizllthR0dyjFrkjv/8+g826s6jkdxJ70Gjx1nPPIMFBPgc5LGC63hhL1k/KAdKN 8pLAFSXYasMUkZWMLByxd8smyOPn+I0ZDjxCLOFrdw9nCAepb79V6PBlZpdj5794xvx9 vYLhp4cDtEFdc0jPovjzNEm6yn9OZAaLnrKXBxzv/UpY4rDie+u44u38cfFULW8AnC5w BejQ== X-Forwarded-Encrypted: i=1; AHgh+Rqreu4gs6VA40NpWKCO+s1ecx2JxDl4sEMmOKYE4MGv7eBNWyGchz4lEZMeSQxt6Q8HOUTIFRDDIZ3qtNQ=@vger.kernel.org X-Gm-Message-State: AOJu0Yw7G1uZeO7wZ6PD3NwTZe5ebYZRGd4HkIAoh7N3uFEkjOWepBRG vr/zshBv5CNPiqkxx5hXVKnlC3n56QgVzoSDLI3cRve41tSmb+biYYJf X-Gm-Gg: AR+sD11NLhmTOSShIoWvynirmnp+kKZBrTPOoytKveMZx5BSqqwsieid23x4J5yDugR rNpx3mXyj/Jq1/KYp74H3yPkwMq2aOQ/mKRgb/YQlF1w4P7L5GRrAFPvIqSh31Qo2wwYTBb3tGM TEnQwODGYPCx19sMTsBc+XiZR0njeHQ57S0xWMDFU1rbkbeHyQudwULu4raaeGFEBMDIIjlSih5 ynWgv7Nbs6IDWNVvXJ7KSnAyW/iXep42oKuRqVhCt0xJIialNp1t/cCRQmnBZ/BLqprJMV8rH85 iA2+dvriBApgQqHaOF8yLn6gT6uSOBTUjQJ7XkX5EUkOdHpYfGToUtsjGgRWCyAmk9uf7yGUGXy +jHOvh46NN77CMUpg4WuYcKlFA7E2Kig6poYD72OsYZL4keGd9z6J/YtaOf7Tx1CfoI94HFpnQg eQHyE7aZVLMlylkFzwXU1n++p583WWLGscEKoCfR7vzBb3PRbNEesnhshh1qPA X-Received: by 2002:a17:90b:35cc:b0:38f:5828:a40c with SMTP id 98e67ed59e1d1-3930151d000mr5624859a91.10.1786537509394; Wed, 12 Aug 2026 05:25:09 -0700 (PDT) Received: from ubuntu.. ([219.241.133.184]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-392f933f600sm3419108a91.2.2026.08.12.05.25.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 05:25:08 -0700 (PDT) From: Rihyeon Kim To: kbusch@kernel.org Cc: hch@lst.de, sagi@grimberg.me, axboe@kernel.dk, justin.tee@broadcom.com, nareshgottumukkala83@gmail.com, paul.ely@broadcom.com, kch@nvidia.com, linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org, syzbot+f58e57380a6083c4041d@syzkaller.appspotmail.com Subject: [PATCH v2] nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails Date: Wed, 12 Aug 2026 21:25:03 +0900 Message-ID: <20260812122503.196828-1-rihyeon8648@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit nvmf_create_ctrl() frees opts when ->create_ctrl() returns an error, so a transport must not free it on its own error paths. nvme_fc_ctrl_free() therefore only calls nvmf_free_options() while ctrl->ctrl.opts is still set, and nvme_fc_init_ctrl() clears that pointer before its last put. It only does so on the fail_ctrl: path. When nvme_add_ctrl() fails, nvme_fc_init_ctrl() jumps to out_put_ctrl: instead, so nvme_fc_ctrl_free() still sees ctrl->ctrl.opts set and frees opts, and nvmf_create_ctrl() frees it again. Reproduced with nvme-fcloop and failslab by failing the kvasprintf() in dev_set_name(), called from nvme_add_ctrl(): BUG: KASAN: slab-use-after-free in nvmf_free_options+0x30/0x190 nvmf_free_options+0x30/0x190 drivers/nvme/host/fabrics.c:1284 nvmf_create_ctrl drivers/nvme/host/fabrics.c:1374 [inline] Freed by task 5534: nvme_fc_ctrl_free drivers/nvme/host/fc.c:2374 [inline] nvme_fc_init_ctrl+0xe17/0x1450 drivers/nvme/host/fc.c:3605 Without KASAN, opts is freed twice. nvme-tcp and nvme-rdma reach the same error path, but their free_ctrl only frees opts once the controller is on the global list, so they are not affected. Move the clear down to out_put_ctrl:, which both error paths pass through. The same injection then returns -EIO without a report. Fixes: 1a9e218195a5 ("nvme: split device add from initialization") Cc: stable@vger.kernel.org Reported-by: syzbot+f58e57380a6083c4041d@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=f58e57380a6083c4041d Suggested-by: Keith Busch Assisted-by: Claude:claude-opus-5 Signed-off-by: Rihyeon Kim --- Changes since v1: move the existing clear from fail_ctrl: down to out_put_ctrl: rather than adding a second one (Keith). Re-tested by sweeping fail-nth 1..200 over the connect write with fcloop and failslab, which reaches both labels: unpatched reports at 17, this passes 200/200. v1: https://lore.kernel.org/linux-nvme/20260811125310.165487-1-rihyeon8648@gmail.com/ drivers/nvme/host/fc.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/nvme/host/fc.c b/drivers/nvme/host/fc.c index 04363b9c4489..a35ed9c8c212 100644 --- a/drivers/nvme/host/fc.c +++ b/drivers/nvme/host/fc.c @@ -3593,14 +3593,15 @@ nvme_fc_init_ctrl(struct device *dev, struct nvmf_ctrl_options *opts, cancel_work_sync(&ctrl->ctrl.reset_work); cancel_delayed_work_sync(&ctrl->connect_work); - ctrl->ctrl.opts = NULL; - if (ctrl->ctrl.admin_tagset) nvme_remove_admin_tag_set(&ctrl->ctrl); /* initiate nvme ctrl ref counting teardown */ nvme_uninit_ctrl(&ctrl->ctrl); out_put_ctrl: + /* the caller frees opts when we return an error */ + ctrl->ctrl.opts = NULL; + /* Remove core ctrl ref. */ nvme_put_ctrl(&ctrl->ctrl); base-commit: 0ce37745d4bfbc493f718169c3974898ffec8ee7 -- 2.43.0