Thread (1 message) 1 message, 1 author, 2021-08-16

Re: [syzbot] KASAN: use-after-free Read in bdev_evict_inode

From: Christoph Hellwig <hch@lst.de>
Date: 2021-08-16 09:34:58
Also in: lkml

On Sun, Aug 15, 2021 at 09:49:30PM +0800, Hillf Danton wrote:
After putting bdi in wb_exit(), wb->bdi is no longer stable. To fix the uaf,
add the WB_put bit to avoid derefering a unstable pointer.

Only for thoughts.
This doesn't help with the fact that the bdi needs to be alive
until after inode_detach_wb is called.  I posted a patch for that last
week, although I'm about to post a v2 as there are more lingering issues
in this area.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help