* [PATCH] ext4: save converted extent before merging
@ 2026-09-30 13:45 Jérémy Jean
2026-09-30 13:53 ` sashiko-bot
2026-10-01 6:06 ` Ojaswin Mujoo
0 siblings, 2 replies; 3+ messages in thread
From: Jérémy Jean @ 2026-09-30 13:45 UTC (permalink / raw)
To: tytso
Cc: Andreas Dilger, Baokun Li, Jan Kara, Ojaswin Mujoo, ritesh.list,
Zhang Yi, linux-ext4, linux-kernel, Jérémy Jean, stable
In ext4_split_convert_extents(), merging can release the leaf holding
the extent pointed to by ex. The later extent status cache update can
then dereference freed memory, causing a use-after-free. KASAN reports:
BUG: KASAN: use-after-free in ext4_split_convert_extents.constprop.0+0xb98/0xc80
Read of size 2 at addr ff11000002547034 by task fixture/65
Save the converted extent before merging and use the copy for the cache
update. This also avoids using the old extent slot after a merge with
the left neighbour.
Fixes: 716b9c23b862 ("ext4: refactor split and convert extents")
Cc: stable@kernel.org
Assisted-by: LLM
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
---
fs/ext4/extents.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
index 76038b6..f5a3880 100644
--- a/fs/ext4/extents.c
+++ b/fs/ext4/extents.c
@@ -3830,6 +3830,7 @@ static struct ext4_ext_path *ext4_split_convert_extents(handle_t *handle,
ext4_lblk_t eof_block;
ext4_lblk_t ee_block;
struct ext4_extent *ex;
+ struct ext4_extent converted_ex;
unsigned int ee_len;
int split_flag = 0, depth, err = 0;
bool did_zeroout = false;
@@ -3887,6 +3888,9 @@ convert:
else if (flags & EXT4_GET_BLOCKS_CONVERT_UNWRITTEN)
ext4_ext_mark_unwritten(ex);
+ /* Merging can move ex or release the leaf containing it. */
+ converted_ex = *ex;
+
if (!(flags & EXT4_GET_BLOCKS_SPLIT_NOMERGE))
/*
* note: ext4_ext_correct_indexes() isn't needed here because
@@ -3897,6 +3901,7 @@ convert:
err = ext4_ext_dirty(handle, inode, path + depth);
if (err)
goto err;
+ ex = &converted_ex;
}
/* Lets update the extent status tree after conversion */
--
2.47.3
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] ext4: save converted extent before merging
2026-09-30 13:45 [PATCH] ext4: save converted extent before merging Jérémy Jean
@ 2026-09-30 13:53 ` sashiko-bot
2026-10-01 6:06 ` Ojaswin Mujoo
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-30 13:53 UTC (permalink / raw)
To: Jérémy Jean; +Cc: tytso, linux-ext4
> In ext4_split_convert_extents(), merging can release the leaf holding
> the extent pointed to by ex. The later extent status cache update can
> then dereference freed memory, causing a use-after-free. KASAN reports:
>
> BUG: KASAN: use-after-free in ext4_split_convert_extents.constprop.0+0xb98/0xc80
> Read of size 2 at addr ff11000002547034 by task fixture/65
>
> Save the converted extent before merging and use the copy for the cache
> update. This also avoids using the old extent slot after a merge with
> the left neighbour.
>
> Fixes: 716b9c23b862 ("ext4: refactor split and convert extents")
> Cc: stable@kernel.org
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930134516.397754-2-Jeremy.Jean@oss.cyber.gouv.fr?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] ext4: save converted extent before merging
2026-09-30 13:45 [PATCH] ext4: save converted extent before merging Jérémy Jean
2026-09-30 13:53 ` sashiko-bot
@ 2026-10-01 6:06 ` Ojaswin Mujoo
1 sibling, 0 replies; 3+ messages in thread
From: Ojaswin Mujoo @ 2026-10-01 6:06 UTC (permalink / raw)
To: Jérémy Jean
Cc: tytso, Andreas Dilger, Baokun Li, Jan Kara, ritesh.list, Zhang Yi,
linux-ext4, linux-kernel, stable
On Wed, Sep 30, 2026 at 01:45:17PM +0000, Jérémy Jean wrote:
> In ext4_split_convert_extents(), merging can release the leaf holding
> the extent pointed to by ex. The later extent status cache update can
> then dereference freed memory, causing a use-after-free. KASAN reports:
>
> BUG: KASAN: use-after-free in ext4_split_convert_extents.constprop.0+0xb98/0xc80
> Read of size 2 at addr ff11000002547034 by task fixture/65
>
> Save the converted extent before merging and use the copy for the cache
> update. This also avoids using the old extent slot after a merge with
> the left neighbour.
>
> Fixes: 716b9c23b862 ("ext4: refactor split and convert extents")
> Cc: stable@kernel.org
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
> ---
Hey Jeremy,
thanks for the fix. I'm working on a patch that has some more fixes in
this area but your fix looks good standalone.
Feel free to add:
Reviewed-by: Ojaswin Mujoo <ojaswin@linux.ibm.com>
Regards,
ojaswin
> fs/ext4/extents.c | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
> index 76038b6..f5a3880 100644
> --- a/fs/ext4/extents.c
> +++ b/fs/ext4/extents.c
> @@ -3830,6 +3830,7 @@ static struct ext4_ext_path *ext4_split_convert_extents(handle_t *handle,
> ext4_lblk_t eof_block;
> ext4_lblk_t ee_block;
> struct ext4_extent *ex;
> + struct ext4_extent converted_ex;
> unsigned int ee_len;
> int split_flag = 0, depth, err = 0;
> bool did_zeroout = false;
> @@ -3887,6 +3888,9 @@ convert:
> else if (flags & EXT4_GET_BLOCKS_CONVERT_UNWRITTEN)
> ext4_ext_mark_unwritten(ex);
>
> + /* Merging can move ex or release the leaf containing it. */
> + converted_ex = *ex;
> +
> if (!(flags & EXT4_GET_BLOCKS_SPLIT_NOMERGE))
> /*
> * note: ext4_ext_correct_indexes() isn't needed here because
> @@ -3897,6 +3901,7 @@ convert:
> err = ext4_ext_dirty(handle, inode, path + depth);
> if (err)
> goto err;
> + ex = &converted_ex;
> }
>
> /* Lets update the extent status tree after conversion */
> --
> 2.47.3
>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-01 6:06 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 13:45 [PATCH] ext4: save converted extent before merging Jérémy Jean
2026-09-30 13:53 ` sashiko-bot
2026-10-01 6:06 ` Ojaswin Mujoo
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.