From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f47.google.com (mail-qv1-f47.google.com [209.85.219.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 13F6C339380 for ; Mon, 10 Aug 2026 17:32:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.47 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786383154; cv=none; b=CprnXftQZ+KJeR+6lwHCzuCCWX4LT2vRRZYyalqiZhBvLW8VNwz9Loc6V7mH1aDmKzjFmSlc/Vy4TgL6/fn+MLhYGNhiBNeAj8L4ZjDcuS4QvkoaVTTuAZ2ORPHkkoUqeOPfhocdudS7OofX3CwK6FVGbN+o8juGHoRN/oCCjU0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786383154; c=relaxed/simple; bh=zjJIWqNtwF0cifNRQPhnYI2EfeYf2B2tY/WqOA+v0m8=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Bh6PZ73yFYb/npIOTJsN86fnRqVZf8dCNhQeCBcIP5YVUNJG5kH7tZFEjB9k0vtXAeWE2pPUyrqfKpvow5C3XfrFBC6l0NosscbKPIKyfypxu4R5dq+LrG2BAWS4yav4j1JsxftYHZ1ZM9XpOJPnWr48vogKGGzVyOCmQs6lqr4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca; spf=pass smtp.mailfrom=ziepe.ca; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b=bk2NQ6TN; arc=none smtp.client-ip=209.85.219.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b="bk2NQ6TN" Received: by mail-qv1-f47.google.com with SMTP id 6a1803df08f44-907ae240ac3so8509536d6.0 for ; Mon, 10 Aug 2026 10:32:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; t=1786383152; x=1786987952; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=VBWupQnXAvbyYBXOH1+tP3/NFYquot2qJ912f9iatvM=; b=bk2NQ6TNba/pzhF+4j6wKRhd1DxdKvqxkUmeC22DCFjWZEEhFrpmpUpvq9zWoJoLVP 4+iphIYVP+voE8mveMk8BT/F4eyrpydRf4diqNlHhSiT4BqPqMwltY3e8voeOs+ceZcy RPy9PB8CEOgz/AfNGT6YoE3aSU5ZjuszC9lekin9p/N3C2w5BkkOkNR5n1mFPM8Q5TVc LBaUrKyvMsS08v9WF6vg6ZyAHkD3pfNAzVZut4DtDuWyIf55Qq7bjNFRJpEnsWk+y1vc ZiOy88MG8x0qCEIY+aD6yPpG5X/JCnIQ5KLbKo/h18+vi2eEGh0SJrPsRdHb9qVIoQaA xdfw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786383152; x=1786987952; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=VBWupQnXAvbyYBXOH1+tP3/NFYquot2qJ912f9iatvM=; b=Ae+hF8GQKUYp3xxvEdjlErCzV/rQ15wRP+jj1tlA94Kl18tj8SWk0gVMhr5tF9hnFS 3QDDIUNS5KmXC6S4GsAIiaItGpKgU5v1rd1jx2hshYnlZYACFSURqMQdaG6/EeAiD+Ap 1emTjEIHer25O0zHW/KIEVxQxDyIejLsFfgZ+q3/YpDQvVzg12LenFrRaGSk1cnJs9vJ 0r01BUcaDbZGblTkUtv6qpqTrQ9INjHAFY8NWUqhuk2CUDl/1lNWIH4wRYKV0qhQy/9u kEK7x2yJvBpqFB9nROZpfxVcGVPt6J/Iox0bnbCpafqwzSAvvwPqiBu+46A747JLG1dG /MxA== X-Forwarded-Encrypted: i=1; AHgh+RpHQVYOuKpHkdXodASz+KF8abjUWKqrJze+I784EUxi89TXFJ09DXT6vX7Ym1zExgYGUMw4PMDYmGEggTc=@vger.kernel.org X-Gm-Message-State: AOJu0YxRMofLSdhZSlFty+ngvM4uGd9Pffcf1FaxFg5MVgyZ8aegS0cm Esnzkq3SW59YutK3oSoVl/oOBcLHZB2JOTsUpzvvDYG8momtY5nFtxJvD7y9ZtF0q3o= X-Gm-Gg: AR+sD10Rged/x4bAMQwZEaBUqEgRhZnEQIUEHAoENMvg3M1ftwJv+u9RTluQEwCMHZF gTeJPb5K6WUqW1zuqyqTmZ4Ir0hax2nxlYjLvBrxp526tW+BJwLnmnUCxFAE4WEoew8Iv36kGlF Rtom2UBI4/i66y+iOXTg/oVv5bGPt+A0/GRknm4A2p2A43OkGQdNMRGAGi1AQm6jJolszmtBKqs mctLZO3UbP/4iIEjIQ4GOfMlwe5zALtqQYhPkI4HNHuDAGep7n4D1nX9Qad27gJ1Ic/bxaPALO+ t46U2n/ujrYIeDuZRmzVWFb+/GVIk5JgeCPu+QQcEmVfhm4kbxnBddgrlfBxWC92nVLxp4+0rLl /1AThUVGsxaEkFjz8pUqt93+31sN6bhIk2qtT32FCP0VuKW5OwN0K/qjgcsjqNkcXXFHhOeow0p SzZAzRrfRQOsnJE12TVDaQGeQK+adag1E6yzvNor30BD98wuTK/8rPJMWTpTPS X-Received: by 2002:a05:6214:540e:b0:907:37d3:1ed1 with SMTP id 6a1803df08f44-908a7100249mr312771366d6.28.1786383151603; Mon, 10 Aug 2026 10:32:31 -0700 (PDT) Received: from ziepe.ca ([142.166.156.215]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-908a91d6ad8sm77283546d6.18.2026.08.10.10.32.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 10:32:31 -0700 (PDT) Received: from jgg by wakko with local (Exim 4.97) (envelope-from ) id 1wtTrS-0000000282q-1SzL; Mon, 10 Aug 2026 14:32:30 -0300 Date: Mon, 10 Aug 2026 14:32:30 -0300 From: Jason Gunthorpe To: Robin Murphy Cc: syzbot , baolu.lu@linux.intel.com, dwmw2@infradead.org, iommu@lists.linux.dev, joro@8bytes.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, will@kernel.org Subject: Re: [syzbot] [iommu?] KASAN: slab-use-after-free Read in free_iova Message-ID: <20260810173230.GQ200537@ziepe.ca> References: <6a7910da.9c11d2ce.289b96.00da.GAE@google.com> <68eebaf3-2427-48c0-93d3-87455ff266fb@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <68eebaf3-2427-48c0-93d3-87455ff266fb@arm.com> On Mon, Aug 10, 2026 at 11:50:28AM +0100, Robin Murphy wrote: > > Freed by task 5327: > > kasan_save_stack mm/kasan/common.c:57 [inline] > > kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 > > kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:584 > > poison_slab_object mm/kasan/common.c:253 [inline] > > __kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285 > > kasan_slab_free include/linux/kasan.h:235 [inline] > > slab_free_hook mm/slub.c:2677 [inline] > > slab_free mm/slub.c:6377 [inline] > > kmem_cache_free+0x182/0x650 mm/slub.c:6504 > > free_iova_mem drivers/iommu/iova.c:237 [inline] > > put_iova_domain+0xcc/0x100 drivers/iommu/iova.c:454 > > ...except that right in between here we've called iommu_dma_free_fq() which > would have already invoked timer_delete_sync() and freed the queue itself. > Wut? I've been feeding syzkaller riddles to the best AI I can get and it is surprisingly good.. So, for this it guesses: --- timer_delete_sync() does stop already scheduled work, but it does not prevent a future mod_timer() from re-scheduling the now-deleted timer. The probable sequence is: 1. A DMA unmap queues an IOVA and sets fq_timer_on = 1 at dma-iommu.c (line 243), but has not yet executed mod_timer(). 2. Concurrent PCI removal frees the device's default IOMMU domain. 3. iommu_dma_free_fq() calls timer_delete_sync() at dma-iommu.c (line 274). Because the timer is not pending at that instant, it returns. 4. Teardown frees the flush queue and all IOVA-tree nodes through put_iova_domain() (line 446). 5. The unmap path resumes and executes mod_timer(), rearming a timer embedded in the soon-to-be-freed DMA cookie. 6. fq_flush_timeout() later runs and calls free_iova_fast(). It traverses the already-destroyed IOVA rbtree, producing the reported UAF in private_find_iova() (line 275). --- Which seems plausible to me.. So it is a bug in a driver allowing a dma API operation to be outstanding after it has been removed? syzkaller console showed it did trigger a remove of a PCI function: open("./sys/bus/pci/devices/0000:00:01.0/remove", O_WRONLY) write(fd, "1", 1) But I couldn't guess what device that was, if someone from syzkaller land can clarify what they have plugged in there it might help. The AI guessed on a GCE VM it was a display adaptor, but I don't see how it could know that. It would be a nice improvement to the CONFIG DMA DEBUGGING to keep track of the driver bound state and blow up directly on all these forbidden combinations. Jason