From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f172.google.com (mail-pl1-f172.google.com [209.85.214.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D9CB51DE2D5 for ; Thu, 16 Jan 2025 10:51:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1737024698; cv=none; b=ISf/Chyr2xBuXmVyeMFLFr8Cz33xUKvh1k6Op2XBayzYT5i+8ArjhFfzvPAKbyD7hILY+CoAHiCmXkd53ZTCufP2rkcykXitcFzJHhiv+whG3kc9vkVw4EIRojrzzI8LBVkTYzq34nEdElDQIbF7IG3pHZu6cwtIAq+dSfesVFw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1737024698; c=relaxed/simple; bh=hIqU3WjqFPIXgZjEQF4bV60VkQ6/dUcrp1POSG/T6fg=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=c2cbR7nqG9BcAf9ivhIqaGp65U9RJ1wJ53sQuzJ+Tl1qB81pozu3HS/53p9hsLnwO16zoq/aJ+5dfcNRhGo2yVr3PVupVDY+h8pUaJ1p60tfu90Hbx+murPVIPkEV4WWTJUgWwPaBxWd5rqQEsTPnUddbIRni/kt/A+MWOKIIFE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=eBYBL9Eq; arc=none smtp.client-ip=209.85.214.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="eBYBL9Eq" Received: by mail-pl1-f172.google.com with SMTP id d9443c01a7336-2165448243fso16482325ad.1 for ; Thu, 16 Jan 2025 02:51:36 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1737024696; x=1737629496; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=zLSalBK2cp1s32e3wtIvQJt/Bo+QRnnBvaALwbyzbKQ=; b=eBYBL9Eqccy6zfOs0O055FGkbsguPgx9Os3AVDHiOnphRUkBVhYzUV4i24XGL0lH5o mNc9vodMl+Sytm63pU2DnHlaB1BKcJT5IwqqS0eAJqn56Og48Mvn+D/z2IqQzoV6MUFh L3H/5QCoM2H5lpcZkoycYvQqmmk/827HFhtGMCnPUhOyFcEEGdYsm6v6IhGzmJcjYzNE 35FCOCYr0MXhSNUbvgSxElw4EMcl6cqxw5Y8WqBUll9QJfaEsZHmTs3awcYE2vi76QPl 1wIo8U/xmFa/UG6Yk5xMs3CkMkgHobpZ9Xo7uQjMTojry71gKfk1VMhA+J4Ar2OkTAnv RJ4A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1737024696; x=1737629496; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zLSalBK2cp1s32e3wtIvQJt/Bo+QRnnBvaALwbyzbKQ=; b=cT51WdJjkNhALmflDS88sXKLP7/aOMTRAIN/NzkgcQSLTAZmoWKq1Hpc8lXBDEHj9K x9dTtlLg0zvtCw5mT5ubGpy68hs+Axl88IZrPLZowMAdN0xMYdcwLnHW5Nyy2G3oMqji ba01/YejeKkLhJd4XvQ84qy3DUKeE3OJgFREB9Jg5PD+eKbx/eKPxjsOEVIgT7dcSBf5 72GNh7boz+gr+Ako/3pYPL5zrwoLsaJvoY7mpbpSzmSfNW+hbsVBKDcsOGU2ZfioUZu2 fJF7vFTAZCpcjZiqgQk9PbZ//TNrLQGz99EcqenfGsQ9qRqO8PPisCVFKM/viE9vrtqo U/zw== X-Forwarded-Encrypted: i=1; AJvYcCUh1c90NoEQ70nMRlOQKWXsDY3cnGfQzG5qQz7p486hVn5MezFsoIcaGTmZ9NGaN3m8MSXw/7rbqMldzP4=@vger.kernel.org X-Gm-Message-State: AOJu0YxaQMUZh1Zw+4uod4kVHqUXBpz3l+Y4mkGhbYLKKcfH2yT/C6iz lIYxToFgf6ZZi9aDKoKuM9pHnYf4qtqJcDHElacGd1iHqaRCk7+V X-Gm-Gg: ASbGncu5sTn6LjsHBxPgR5O2sQiX8q2Qv39/w5gnkZtw+FCqSM2k2TVU4PqJI+J1QfD GJI5gvTer/qqMK/KSxSFD4z8T66DC7Q2O+Ce+7ktsjfsG6RImQvJ2SwApw0oU3g+sXr1BDdMPtn +LBy7YOY+Fz8s7H8eFK5tUdw+0LvEQiE+CCF67MPAYTwPKErBhJWxZ6zyUUBUH6hkdI7BrYKX8H eyiE2GHqZrImWCxcxFEe60IidNIyZz+tqEEr7caolKTDMRlR5We+bCPER7ReBrVRmpbeW6M92ik BXrNcL7qTDzlWhdLrjh8GSps+w== X-Google-Smtp-Source: AGHT+IEHPGFYOqzGLx/aw05SqfG2axQjWitLPHOusv9anchfeQTQl/37IT/V6ace040xB1aUfE5vDw== X-Received: by 2002:a17:903:1251:b0:216:4122:925f with SMTP id d9443c01a7336-21a83f56d67mr518905535ad.14.1737024696078; Thu, 16 Jan 2025 02:51:36 -0800 (PST) Received: from ?IPV6:2402:f000:5:2800:f432:8f4d:a17f:4da5? ([2402:f000:5:2800:f432:8f4d:a17f:4da5]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-21a9f13b0f6sm96796725ad.67.2025.01.16.02.51.34 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 16 Jan 2025 02:51:35 -0800 (PST) Message-ID: <76138c79-0718-4917-a452-5ec759b52d27@gmail.com> Date: Thu, 16 Jan 2025 18:51:31 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [BUG] mei: a possible use-after-free caused by concurrency execution To: Greg KH Cc: tomas.winkler@intel.com, arnd@arndb.de, LKML , Jia-Ju Bai References: <2025011641-seventeen-curse-e404@gregkh> Content-Language: en-US From: Tuo Li In-Reply-To: <2025011641-seventeen-curse-e404@gregkh> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 2025/1/16 17:51, Greg KH wrote: > On Thu, Jan 16, 2025 at 05:26:33PM +0800, Tuo Li wrote: >> Hello, >> >> Our static analysis tool has identified a potential use-after-free caused >> by concurrency execution in drivers/misc/mei/main.c. >> >> Consider the following execution scenario: >> (The line numbers can be referred to >> https://elixir.bootlin.com/linux/v6.12/source/drivers/misc/mei/main.c) >> >> mei_release() //Line 112 >> cl = file->private_data; //Line 114 >> mutex_lock(&dev->device_lock); //Line 123 >> kfree(cl); //Line 149 >> file->private_data = NULL; //Line 152 >> mutex_unlock(&dev->device_lock); //Line 154 >> >> mei_read() //Line 169 >> cl = file->private_data; //Line 172 >> mutex_lock(&dev->device_lock); //Line 184 >> cb = mei_cl_read_cb(cl, file); //Line 200 >> cl_dbg(dev, cl, ...); //Line 275 >> mutex_unlock(&dev->device_lock); //Line 276 >> >> If mei_release() and mei_read() can execute concurrently and the execution >> order is 114, 172, 123, 149 (free), 152, 154, 184, 200 (use), 275 (use), >> 276, a possible use-after-free can occur. > > How can release run at the same time read happens? release only happens > after all references are dropped, right? > >> Our static analysis tool reports this use-after-free when analyzing Linux >> 6.12. The tool deduces lock() and unlock() pairs with alias analysis. It >> then applies data flow analysis to detect use-after-free across >> synchronization points. >> >> I am not quite sure whether this possible use-after-free is real and how to >> fix it if it is real. > > Test it and see! And if you feel a fix is needed, please provide a > patch. > > thanks, > > greg k-h Hello, I really appreciate the feedback! I apologize for the inconvenience this report has caused. Sincerely, Tuo Li