From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lf1-f44.google.com (mail-lf1-f44.google.com [209.85.167.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 471B83FE35C for ; Thu, 30 Jul 2026 09:25:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785403511; cv=none; b=j7LWDG0J2ne/c9375opR3ox0IEETTH9Zr6xTll0GP1OUleD6nbAVS8CuVwl6VgsFR2OurpRq+7Ggmz0w3B8sfB1Upv2IieYp3pGmpTugfgtm+UCJvHNW4LY7oAtrym5QrE6uqHHPLL1KMD30NLgPiY/5SOpUhp82QihQ81AUn94= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785403511; c=relaxed/simple; bh=lxgIN3am8YlW+d3zrF8L2Yz4U0h0EXHa7i2yQa4P/pk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=m9bwmbuYidAU7HzYd5s4N0PhsmM9lu/yw0vbfT9DVtL9R2/zc4EHCk+WOXuOe2DXe90zon2WPWiKZDVvB9s0a96ZUPlXoOe7s8rR4Kt7GwBnXop2WVaeTCnpa5X62CJPI/bVvsLV4mj6WrOXrzMcaZ+g5i8oNYZfcxbSWupvqK4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=bS2zp3og; arc=none smtp.client-ip=209.85.167.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="bS2zp3og" Received: by mail-lf1-f44.google.com with SMTP id 2adb3069b0e04-5b28c91fba5so719672e87.1 for ; Thu, 30 Jul 2026 02:25:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785403508; x=1786008308; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=liSmhUSKLeQPFTSZNs2U0fS1bdGANjrXSt6COVD0ZoI=; b=bS2zp3oghw/T2QO6N6XkqLEOE35iXJEH6eJuIjOLCB1LonBpbv53e3zShQy3iFwSSP Av4reM5n8E7JE1Qx6EEFSLFeiEiuhkQE7PaxB1BRCFSdpxIec50rvsM66jQ5KoXa0dDV BJACnsvp7bs2yGcSEeed0xLUD0VN+pF/dyKiJndzuxXr0FmrIlB86cQAcHQDDr0/Ced+ rpcaL1WvwDXRw4DshnmdwjIu5heBQaAtguuSCW1IT4buqOsUKyz/YOkC51ZlL307mpN1 BANedLooI3zl3/R8/FM2YbocUYFahS+lMYIsWHvSrE5NmDRfJ1zFMy3mM0CgyGVQ94ED KHFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785403508; x=1786008308; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=liSmhUSKLeQPFTSZNs2U0fS1bdGANjrXSt6COVD0ZoI=; b=XgCJFx+rjtXaz7G8G6Dr4hZZeXE8ik2ZcyZqBZipN345fgyEJSiKoAlucSfVxexIVr poiavW/jl3XK//72pU7nKaAo+R2EaXKDq3YcyCLeL8HQBztMCY9iOzaUq9Kyqu31mYiC CpMtd2Zrk2XvmZzGuy2fL8+QPpoRKt5scxNoj3nIeqXyGWkFAWZ81kHhjTSwtkputiY2 AKa/FEQhluNlhcPs4HRSOsVu1Sm9oCGVZfmQIbvj/FHe6mhuE8NHPMLd9p53ROMi+LfB Uhrv7DsVJmZWx81Xkv8xGt7nLlZRxvMVcDPzkcDiKVGBjY1aUCyTxdHjEfgCD4uodsm4 sk1g== X-Gm-Message-State: AOJu0YzW57nwxqxTUL+1m0f/1/aekv7NI3cFS3aZnW6FQ6sV7fZ+7lhx CJJ5stTnXbrBttKZ+COD2lZp+B0T/TvWWhURgQota9BbQ9eM026MCtA/ X-Gm-Gg: AR+sD12haq9TcfwLXP10FTvwGplmsoTeK3OtoQy5qk2HoIq6YPfjtYZIQxw8csG9xkh moK/WmKxCgfTbAZsEbvKe3WQa9sXz1DZdYZ3nw06aguyVqZSHs1LjjEASnKtC0mgNA9rhlhjczC WEYeHeN4nJ7wsD6Q8DHvKIc9RHNGbj3odHwtlTQwoGqCNDdnrs7coN+LfNVHo8pu0Xb8APhp2pB trKVvuxtOKrLGKOGrYaf2tt3rBua82ChfRAfUXcqKN+Lc4yuKC2dlPp4FH46t/SCYBAEFdzaAYM Da/21FUtK9RZS+8JsLDh0Gn1/uTM4YVlgK1hfLpPs9X0/IEIlcm6y6I1/iC2FAsOShT0jGD2zwb NK6/WdEPbdoe/IkFd7Iy7AYqJhWzUDaxIDYbxd4iuqZo84+S7ps4GPUabNCvQW7iyfg08pI9a4+ jgL0JqkZNg+p6YJ6K/jyqpgsWCx69oO672j9uTZz2jl+D/dgWIcCfEJADzsBuLJ5xuNxNMfMtqK CgXNobSeaKlkdHKr1HFI6biTAEY/4KsgrTWj/7iXZEg46+KZDsQ3FbWlqf8qDFyNm8MqS7QclcQ Yw== X-Received: by 2002:a05:6512:1084:b0:5ae:a9ed:35a7 with SMTP id 2adb3069b0e04-5b2db9bd4d2mr289926e87.32.1785403508012; Thu, 30 Jul 2026 02:25:08 -0700 (PDT) Received: from debian.localdomain (95-25-164-153.broadband.corbina.ru. [95.25.164.153]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5b2db9ba970sm224654e87.51.2026.07.30.02.25.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 02:25:07 -0700 (PDT) From: Igor Putko To: Andreas Hindborg , Breno Leitao Cc: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, Igor Putko , syzbot+6b16e3d085833cbf3e25@syzkaller.appspotmail.com Subject: [PATCH] configfs: fix slab-use-after-free in configfs_get_config_item() Date: Thu, 30 Jul 2026 12:25:02 +0300 Message-ID: <20260730092502.5913-1-igorpetindev@gmail.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When configfs_symlink() resolves the target via get_target(), it uses kern_path() which takes a reference on the target's dentry. If a concurrent rmdir occurs, vfs_rmdir() calls dentry_unhash(). However, because the dentry's refcount is > 1, dentry_unhash() bails out and does not actually unhash it. As a result, when configfs_symlink() subsequently calls configfs_get_config_item(), it finds the dentry still hashed. It then calls config_item_get() on sd->s_element. But since the concurrent rmdir has already proceeded to detach and free the config_item, this leads to a KASAN slab-use-after-free. Fix this by taking configfs_dirent_lock inside configfs_get_config_item() and checking if the CONFIGFS_USET_DROPPING flag is set before taking a reference on the config_item. Reported-by: syzbot+6b16e3d085833cbf3e25@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=6b16e3d085833cbf3e25 Fixes: 7051a3632669 ("configfs: Infrastructure for configfs items.") Signed-off-by: Igor Putko --- fs/configfs/configfs_internal.h | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/fs/configfs/configfs_internal.h b/fs/configfs/configfs_internal.h index acdeea8e2..90d6c7515 100644 --- a/fs/configfs/configfs_internal.h +++ b/fs/configfs/configfs_internal.h @@ -119,12 +119,23 @@ static inline struct configfs_bin_attribute *to_bin_attr(struct dentry *dentry) static inline struct config_item *configfs_get_config_item(struct dentry *dentry) { - struct config_item * item = NULL; + struct config_item *item = NULL; spin_lock(&dentry->d_lock); if (!d_unhashed(dentry)) { - struct configfs_dirent * sd = dentry->d_fsdata; - item = config_item_get(sd->s_element); + struct configfs_dirent *sd = dentry->d_fsdata; + + if (sd) { + /* + * vfs_rmdir() keeps dentry in hash, if d_count > 1. + * Make sure to check the deletion flag while + * holding the lock. + */ + spin_lock(&configfs_dirent_lock); + if (!(sd->s_type & CONFIGFS_USET_DROPPING)) + item = config_item_get(sd->s_element); + spin_unlock(&configfs_dirent_lock); + } } spin_unlock(&dentry->d_lock); -- 2.47.3