[bug report] BUG: KASAN: slab-use-after-free in blkg_destroy+0x34b/0x380

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello,

Found kernel issue about dm-mod blkg_destroy, please have a look if
need more info.
kernel repo : https://github.com/torvalds/linux.git
kernel : 6.2.0.kasan

just found it once and not sure the reproducer

  OK
] Reached target
System Reboot
.
[ 3810.010126] systemd-shutdown[1]: Waiting for process: 119574
(bash), 119566 (rhts-reboot), 119584 (sleep), 119578 (sleep), 119575
(tee)
[-- MARK -- Mon Feb 27 10:25:00 2023]
[ 3890.110979] ==================================================================
[ 3890.118206] BUG: KASAN: slab-use-after-free in blkg_destroy+0x34b/0x380
[ 3890.124825] Read of size 8 at addr ff11000131856820 by task systemd-shutdow/1
[ 3890.131959]
[ 3890.133456] CPU: 8 PID: 1 Comm: systemd-shutdow Kdump: loaded Not
tainted 6.2.0.kasan+ #1
[ 3890.141628] Hardware name: Intel Corporation WHITLEY/WHITLEY, BIOS
WLYDCRB1.SYS.0020.P21.2012150710 12/15/2020
[ 3890.151613] Call Trace:
[ 3890.154065]  <TASK>
[ 3890.156172]  dump_stack_lvl+0x33/0x50
[ 3890.159846]  print_address_description.constprop.0+0x2c/0x3e0
[ 3890.165600]  print_report+0xb5/0x270
[ 3890.169176]  ? kasan_addr_to_slab+0x9/0xa0
[ 3890.173276]  ? blkg_destroy+0x34b/0x380
[ 3890.177117]  kasan_report+0xcf/0x100
[ 3890.180693]  ? blkg_destroy+0x34b/0x380
[ 3890.184525]  blkg_destroy+0x34b/0x380
[ 3890.188190]  ? percpu_ref_kill_and_confirm+0xa7/0x250
[ 3890.193244]  blkg_destroy_all.isra.0+0x101/0x1f0
[ 3890.197863]  blkcg_exit_disk+0x2f/0x70
[ 3890.201615]  disk_release+0x110/0x3f0
[ 3890.205281]  device_release+0x98/0x210
[ 3890.209042]  kobject_cleanup+0x101/0x360
[ 3890.212975]  cleanup_mapped_device+0x255/0x490 [dm_mod]
[ 3890.218219]  __dm_destroy+0x316/0x550 [dm_mod]
[ 3890.222680]  dev_remove+0x230/0x300 [dm_mod]
[ 3890.226970]  ctl_ioctl+0x4e8/0x790 [dm_mod]
[ 3890.231166]  ? __pfx_ctl_ioctl+0x10/0x10 [dm_mod]
[ 3890.235888]  ? kasan_save_stack+0x2e/0x40
[ 3890.239901]  ? kasan_save_stack+0x1e/0x40
[ 3890.243911]  ? task_work_add+0x73/0x210
[ 3890.247751]  ? filp_close+0xf3/0x150
[ 3890.251330]  ? __x64_sys_close+0x2c/0x70
[ 3890.255254]  ? do_syscall_64+0x59/0x90
[ 3890.259009]  ? __pfx___wait_for_common+0x10/0x10
[ 3890.263630]  ? rseq_get_rseq_cs+0x6a/0x660
[ 3890.267733]  ? __fget_light+0x57/0x510
[ 3890.271489]  dm_ctl_ioctl+0xa/0x20 [dm_mod]
[ 3890.275689]  __x64_sys_ioctl+0x128/0x1a0
[ 3890.279617]  do_syscall_64+0x59/0x90
[ 3890.283196]  ? _raw_spin_lock+0x81/0xe0
[ 3890.287035]  ? __rseq_handle_notify_resume+0x64/0xd0
[ 3890.291999]  ? exit_to_user_mode_loop+0xd0/0x130
[ 3890.296617]  ? exit_to_user_mode_prepare+0xb6/0x100
[ 3890.301498]  ? syscall_exit_to_user_mode+0x12/0x30
[ 3890.306290]  ? do_syscall_64+0x69/0x90
[ 3890.310042]  ? do_syscall_64+0x69/0x90
[ 3890.313796]  entry_SYSCALL_64_after_hwframe+0x72/0xdc
[ 3890.318848] RIP: 0033:0x7fb97303ec6b


--

--
dm-devel mailing list
dm-devel@xxxxxxxxxx
https://listman.redhat.com/mailman/listinfo/dm-devel




[Index of Archives]     [DM Crypt]     [Fedora Desktop]     [ATA RAID]     [Fedora Marketing]     [Fedora Packaging]     [Fedora SELinux]     [Yosemite Discussion]     [KDE Users]     [Fedora Docs]

  Powered by Linux