This is a note to let you know that I've just added the patch titled ext4: missing !bh check in ext4_xattr_inode_write() to the 4.19-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: ext4-missing-bh-check-in-ext4_xattr_inode_write.patch and it can be found in the queue-4.19 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From eb6984fa4ce2837dcb1f66720a600f31b0bb3739 Mon Sep 17 00:00:00 2001 From: Vasily Averin <vvs@xxxxxxxxxxxxx> Date: Fri, 9 Nov 2018 11:34:40 -0500 Subject: ext4: missing !bh check in ext4_xattr_inode_write() From: Vasily Averin <vvs@xxxxxxxxxxxxx> commit eb6984fa4ce2837dcb1f66720a600f31b0bb3739 upstream. According to Ted Ts'o ext4_getblk() called in ext4_xattr_inode_write() should not return bh = NULL The only time that bh could be NULL, then, would be in the case of something really going wrong; a programming error elsewhere (perhaps a wild pointer dereference) or I/O error causing on-disk file system corruption (although that would be highly unlikely given that we had *just* allocated the blocks and so the metadata blocks in question probably would still be in the cache). Fixes: e50e5129f384 ("ext4: xattr-in-inode support") Signed-off-by: Vasily Averin <vvs@xxxxxxxxxxxxx> Signed-off-by: Theodore Ts'o <tytso@xxxxxxx> Cc: stable@xxxxxxxxxx # 4.13 Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- fs/ext4/xattr.c | 6 ++++++ 1 file changed, 6 insertions(+) --- a/fs/ext4/xattr.c +++ b/fs/ext4/xattr.c @@ -1388,6 +1388,12 @@ retry: bh = ext4_getblk(handle, ea_inode, block, 0); if (IS_ERR(bh)) return PTR_ERR(bh); + if (!bh) { + WARN_ON_ONCE(1); + EXT4_ERROR_INODE(ea_inode, + "ext4_getblk() return bh = NULL"); + return -EFSCORRUPTED; + } ret = ext4_journal_get_write_access(handle, bh); if (ret) goto out; Patches currently in stable-queue which might be from vvs@xxxxxxxxxxxxx are queue-4.19/ext4-fix-buffer-leak-in-ext4_expand_extra_isize_ea-on-error-path.patch queue-4.19/ext4-add-missing-brelse-add_new_gdb_meta_bg-s-error-path.patch queue-4.19/mm-swapfile.c-use-kvzalloc-for-swap_info_struct-allocation.patch queue-4.19/ext4-avoid-buffer-leak-in-ext4_orphan_add-after-prior-errors.patch queue-4.19/ext4-missing-bh-check-in-ext4_xattr_inode_write.patch queue-4.19/ext4-avoid-buffer-leak-on-shutdown-in-ext4_mark_iloc_dirty.patch queue-4.19/ext4-release-bs.bh-before-re-using-in-ext4_xattr_block_find.patch queue-4.19/ext4-fix-missing-cleanup-if-ext4_alloc_flex_bg_array-fails-while-resizing.patch queue-4.19/ext4-fix-buffer-leak-in-__ext4_read_dirblock-on-error-path.patch queue-4.19/ext4-fix-possible-inode-leak-in-the-retry-loop-of-ext4_resize_fs.patch queue-4.19/ext4-fix-buffer-leak-in-ext4_xattr_get_block-on-error-path.patch queue-4.19/ext4-fix-possible-leak-of-sbi-s_group_desc_leak-in-error-path.patch queue-4.19/ext4-add-missing-brelse-in-set_flexbg_block_bitmap-s-error-path.patch queue-4.19/ext4-fix-buffer-leak-in-ext4_xattr_move_to_block-on-error-path.patch queue-4.19/ext4-avoid-potential-extra-brelse-in-setup_new_flex_group_blocks.patch queue-4.19/ext4-add-missing-brelse-update_backups-s-error-path.patch queue-4.19/ext4-avoid-possible-double-brelse-in-add_new_gdb-on-error-path.patch queue-4.19/ext4-fix-possible-leak-of-s_journal_flag_rwsem-in-error-path.patch