From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f52.google.com (mail-qv1-f52.google.com [209.85.219.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6397041A4E5 for ; Fri, 31 Jul 2026 12:03:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785499437; cv=none; b=BI0Tqdv3G0MG/6w+Z/WS8buMCA4mVh5EcT40fvuGFPfhkd8UC8iQ6CCa4KIl+Ej0gVDmyB/Bec3y24bAHhqA5ue2/UqgCwe30o5dXxQh13va8mj3ZBIHKHcY2h3QlLdK2re311AH1NvXkDWCq1zlmNhvVh1ZLIy5rgvxGhlH38A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785499437; c=relaxed/simple; bh=a3u47kRr3Do278tdnqPPYoZAssH2IdMcqqRKQFentd0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=trg3zSnRQsceDIDKjzKrl559ENrJLTckeL/ubto3I4xSXvcfQdl10YOQh5JpNYOerpXm2H2WLQGNvwz+kMpu5SmEU2gB1/FcWBwJTrKcPCpTXtUrHxbtJ++lJgwJN0QislbwrVNsg2ZWNlm0qcyTPYgjFJYGcfYUJYBMwEH3Xuk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=QZOauCFr; arc=none smtp.client-ip=209.85.219.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="QZOauCFr" Received: by mail-qv1-f52.google.com with SMTP id 6a1803df08f44-8f0d6853360so6698646d6.0 for ; Fri, 31 Jul 2026 05:03:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785499434; x=1786104234; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=BzP4sK4hBb/8A2cn+zbTFn82mSE4pQ11vgzpnhcOkCA=; b=QZOauCFr3xyLEDBIb7cKExLNMMpFwSFMmaSe8Ol+FwpNMQV/RHYreY95FE1EvFzq3R oEA0PI0dsNmdKEUoPgVJOe975hPQazJEqcVpy4kdOGQh9uwz/XPGmHrrulzRoNflemTo Y90f/KjkYnUK55xPM1dbKrFEjAMoX/hpy88ufM8TWhioZW0/eqU8HJ/TfBcRaLU5RjRm 83YuHz/rYn6FWJoJbAiRp690I5ENcWjAz3D368qZtRwFKB+609r+/7ofDoOyQV2mZQ5R jTvC5vpgWgCepdbYi93yyrxvOLRcEkqWa1PMwGY05b7RGLSAeSFOop5PFTfKE2HGrmJe /BYA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785499434; x=1786104234; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BzP4sK4hBb/8A2cn+zbTFn82mSE4pQ11vgzpnhcOkCA=; b=Fp+/AWjGshWjMuZBUDONj0KDqzijQVCgfgQtA3Z1/idTU+93J5JNOwvhkmqtDxg0qy mm3qFc4gFd507r2saGGloUOzO2QzOXmUeGlMgesqH2zTe9CZOXb+QBedWWm7TW/NceeY LGixZhjMCe4QD5AAzRQzblKb04ALskhh05vjqvb7qdyNNQp/pBESjBFuTCZ5DQdNi0Oq xi55h3aXCdO9k4jVkWIdVGfBgUt2ti30QCKk+f/r6WlUusD0SV5FquN0qS3NsWPKGuI1 2rY7wIToTvXR7e/wT5fpf3YMGurcSMXMfNjieGXSKtnVN/uToMMl6r2WNrHMZPO9TeLq VhEw== X-Forwarded-Encrypted: i=1; AHgh+RqxqJRFJ21tpIC/rk3Q0OzUPUaEhnGHC75NO2wRFvYYsp1XKXMN9rhgy5BmJ+pHxgWLYAsFiQbPH8zDIAY=@vger.kernel.org X-Gm-Message-State: AOJu0Yyp3vMP/sZtTotWm8UpANn4RoegcQ3xgp75U2HL2mr1TbzUO3Mc Kp7p5iKCW8Wupzt38RJ74653hcN5T9Xp9LXa+Pu2BbCdZzlzQji6sDoht5+UNrYAzqBf0tVPwEN r3+Yj X-Gm-Gg: AR+sD13n0nURt4wrKSxX5w5BaT4edeViJo6zKDlZGDAUhgV8y7u0VhJRBGuYMWHK1hG MZDvFONOJTmn5Ag7u1gL8MUB9RM/ZjSOJW2D7fzdOOJxjRjnTicPu8UaWLOfUzuPsXAGQVVnJPO EedBMENtdEP13LqM8dacQvTezRL9L8pdY0xwwe97UCs+pnrxd2L5U25TRq0aQBVqGZb6K/+OPso MRVYG1ycNvI1tCAckBDYK2BD+L5x3DpG3LQJFbgq/bPQZmyR212Pv0GhNLajtaLV2W5hEffs8VG yEXGgW+b+1R0iFoKetDCf3RZCfT2rObdZXXm3yEFlVgEV96TCOiLFaDYbk/kjxnhVUBhlErPBJJ jl+QE+lO6N5p+IztAc/xWaTIW+f/7l/JRoo/7M7wWyBGIng5Oqyub8HCJY6EvDE9YXEHiKuV4Oz 9V+1Q7dguwl+q15zK5pROdtsaX9ELyCzUgV2PK9CchssFB/2mJPQ3Vp9bKIQLyqq3vTg== X-Received: by 2002:a05:6214:2025:b0:8f1:440c:7f81 with SMTP id 6a1803df08f44-908421a38e2mr30020526d6.4.1785499434242; Fri, 31 Jul 2026 05:03:54 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-908435def8fsm8686026d6.38.2026.07.31.05.03.53 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 05:03:54 -0700 (PDT) From: David Lee To: miklos@szeredi.hu Cc: David Lee , Kyle Zeng , Dominik 'Disconnect3d' Czarnota , fuse-devel@lists.linux.dev, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] fuse: wait for sync init request after abort Date: Fri, 31 Jul 2026 12:03:52 +0000 Message-ID: <20260731120353.558833-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit After a fatal signal interrupts synchronous FUSE_INIT, request_wait_answer() aborts the channel and returns immediately. If the request is in an FR_LOCKED reply-copy interval, fuse_chan_abort() leaves it for the writer to finish. The synchronous caller can then free the fuse_init_args that owns the reply destination while the writer is still copying into it. Wait for fuse_request_end() after aborting the channel. This keeps the synchronous caller's reply storage alive until any locked copy has finished, while preserving the fatal-signal abort behavior. Fixes: 204aa22a686b ("fuse: abort on fatal signal during sync init") Cc: stable@vger.kernel.org Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. Assisted-by: Codex:gpt-5.6-sol gpt-5.5-cyber Signed-off-by: Kyle Zeng --- Trail of Bits has a reproducer for this bug that triggers a KASAN use-after-free and can share if needed. fs/fuse/dev.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/fs/fuse/dev.c b/fs/fuse/dev.c index 5763a7cd3..deee1585d 100644 --- a/fs/fuse/dev.c +++ b/fs/fuse/dev.c @@ -725,6 +725,8 @@ static void request_wait_answer(struct fuse_req *req) if (req->args->abort_on_kill) { fuse_chan_abort(fch, false); + wait_event(req->waitq, + test_bit(FR_FINISHED, &req->flags)); return; } -- 2.53.0