Re: [PATCH V4] Fix NULL dereference in super_by_fd

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



ping

On 2022/12/21 20:05, Mariusz Tkaczyk wrote:
> On Wed, 21 Dec 2022 17:37:52 +0800
> Li Xiao Keng <lixiaokeng@xxxxxxxxxx> wrote:
> 
>> When we create 100 partitions (major is 259 not 254) in a raid device,
>> mdadm may coredump:
>>
>> Core was generated by `/usr/sbin/mdadm --detail --export /dev/md1p7'.
>> Program terminated with signal SIGSEGV, Segmentation fault.
>> #0  __strlen_avx2_rtm () at ../sysdeps/x86_64/multiarch/strlen-avx2.S:74
>> 74		VPCMPEQ	(%rdi), %ymm0, %ymm1
>> (gdb) bt
>> #0  __strlen_avx2_rtm () at ../sysdeps/x86_64/multiarch/strlen-avx2.S:74
>> #1  0x00007fbb9a7e4139 in __strcpy_chk (dest=dest@entry=0x55d55d6a13ac "",
>> src=0x0, destlen=destlen@entry=32) at strcpy_chk.c:28 #2  0x000055d55ba1766d
>> in strcpy (__src=<optimized out>, __dest=0x55d55d6a13ac "") at
>> /usr/include/bits/string_fortified.h:79 #3  super_by_fd (fd=fd@entry=3,
>> subarrayp=subarrayp@entry=0x7fff44dfcc48) at util.c:1289 #4
>> 0x000055d55ba273a6 in Detail (dev=0x7fff44dfef0b "/dev/md1p7",
>> c=0x7fff44dfe440) at Detail.c:101 #5  0x000055d55ba0de61 in misc_list
>> (c=<optimized out>, ss=<optimized out>, dump_directory=<optimized out>,
>> ident=<optimized out>, devlist=<optimized out>) at mdadm.c:1959 #6  main
>> (argc=<optimized out>, argv=<optimized out>) at mdadm.c:1629
>>
>> The direct cause is fd2devnm returning NULL, so add a check.
>>
>> V1->V2: When fd2devnm return NULL, super_by_fd return NULL but not an
>> incomplete 'st' entry. At the same time, add a check in map_by_devnm
>> to avoid coredump.
>>
>> V2->V3: Fix style issues.
>> V3->V4: Change strcpy() to strncpy().
>>
>> Signed-off-by: Li Xiao Keng <lixiaokeng@xxxxxxxxxx>
>> Signed-off-by: Wu Guang Hao <wuguanghao3@xxxxxxxxxx>
> 
> 
> Acked-by: Mariusz Tkaczyk <mariusz.tkaczyk@xxxxxxxxxxxxxxx>
> 
> Coly could you please take a look?
> 
> Thanks,
> Mariusz
> .
> 



[Index of Archives]     [Linux RAID Wiki]     [ATA RAID]     [Linux SCSI Target Infrastructure]     [Linux Block]     [Linux IDE]     [Linux SCSI]     [Linux Hams]     [Device Mapper]     [Device Mapper Cryptographics]     [Kernel]     [Linux Admin]     [Linux Net]     [GFS]     [RPM]     [git]     [Yosemite Forum]


  Powered by Linux