Skip to content

Commit a658a1e

Browse files
Andreas Gruenbachermehmetb0
authored andcommitted
gfs2: Fix NULL pointer dereference in gfs2_log_flush
[ Upstream commit 3526490 ] In gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the log flush lock to provide exclusion against gfs2_log_flush(). In gfs2_log_flush(), check if sdp->sd_jdesc is non-NULL before dereferencing it. Otherwise, we could run into a NULL pointer dereference when outstanding glock work races with an unmount (glock_work_func -> run_queue -> do_xmote -> inode_go_sync -> gfs2_log_flush). Signed-off-by: Andreas Gruenbacher <[email protected]> Signed-off-by: Sasha Levin <[email protected]> CVE-2024-42079 (backported from commit 3429ef5f50909cee9e498c50f0c499b9397116ce linux-6.6.y) [mpellizzer: backported solving merge conflicts due to surrounding instructions which do not affect the patch] Signed-off-by: Massimiliano Pellizzer <[email protected]> Acked-by: ivanhu <[email protected]> Acked-by: Guoqing Jiang <[email protected]> Signed-off-by: Stefan Bader <[email protected]>
1 parent 43e6a04 commit a658a1e

File tree

2 files changed

+6
-1
lines changed

2 files changed

+6
-1
lines changed

fs/gfs2/log.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1094,7 +1094,8 @@ void gfs2_log_flush(struct gfs2_sbd *sdp, struct gfs2_glock *gl, u32 flags)
10941094
lops_before_commit(sdp, tr);
10951095
if (gfs2_withdrawn(sdp))
10961096
goto out_withdraw;
1097-
gfs2_log_submit_bio(&sdp->sd_jdesc->jd_log_bio, REQ_OP_WRITE);
1097+
if (sdp->sd_jdesc)
1098+
gfs2_log_submit_bio(&sdp->sd_jdesc->jd_log_bio, REQ_OP_WRITE);
10981099
if (gfs2_withdrawn(sdp))
10991100
goto out_withdraw;
11001101

fs/gfs2/super.c

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -67,9 +67,13 @@ void gfs2_jindex_free(struct gfs2_sbd *sdp)
6767
sdp->sd_journals = 0;
6868
spin_unlock(&sdp->sd_jindex_spin);
6969

70+
down_write(&sdp->sd_log_flush_lock);
7071
sdp->sd_jdesc = NULL;
72+
up_write(&sdp->sd_log_flush_lock);
73+
7174
while (!list_empty(&list)) {
7275
jd = list_first_entry(&list, struct gfs2_jdesc, jd_list);
76+
BUG_ON(jd->jd_log_bio);
7377
gfs2_free_journal_extents(jd);
7478
list_del(&jd->jd_list);
7579
iput(jd->jd_inode);

0 commit comments

Comments
 (0)