From nobody Sat Jul 25 22:33:37 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 49E3113D51E; Sun, 12 Jul 2026 20:21:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783887682; cv=none; b=ieahMMpu2tijUkCbmQsUv8lOxe1QXhNQ0P7wMig61YsOqiE3yHSuk/pK+ZVaPHEhLqf2Ch7SMflq95ueBQeiS4KvYFlwhGKwHUf0ufDPG8R4D9P3q+UvXp67V7ZWPuZyaWgTFISvRZfcS8ZSlqaIdK6OjQKVzicElvmbSA7EW7I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783887682; c=relaxed/simple; bh=as4ecKyATLLiLU+K7q++TXoFW9MaeyuRw24AA9b8bIc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=I3ObEqCs8mtPbokH8SCZBqtFlNuD6BKQI3Njl6+qTI8+oi/4btEiz/Iw5pFTHcd0QM6fFljMXZx+LYxsWk5UCfqYsISkmQxSxDNj5dCxN2/HatTIoUOEm1nO79+85jDfiDlsU+5jg1GvaCQ7CQLSfAogBsq0Q/yPpT9U/i5YltI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=WPn7vj5N; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="WPn7vj5N" Received: by smtp.kernel.org (Postfix) with ESMTPS id DE0B3C2BCC7; Sun, 12 Jul 2026 20:21:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783887681; bh=as4ecKyATLLiLU+K7q++TXoFW9MaeyuRw24AA9b8bIc=; h=From:Date:Subject:To:Cc:Reply-To:From; b=WPn7vj5Nqp1BQQaCvblGuoiIlqgQDzGxoxPTp81YWe3ssHCC7DVFqjok+meJkO5Ut DLuFJ58iLvjvmT5qB7q4a+ZiQ4aGSiY0kHlNfj3JwxQRltsxtXrE7rsKlVBq1imgdg zyWu66eiJBfe+BPV4+E5ho/5NZ+v0hf8ARhSE2BR1xCzfYYdSsg2AdrWWzQvwYEL4/ DJB7pUzEd4doZrbMvrDBEhoGBqGvNGNxbVBaHMXlQExQAbje+zbdHECT34GG4HIinW x47vEedBxb6krkED73xcEGoaiIoHX31xPE/87S5jVmp+deoVupvDvhLxpB9YrJK9Qd vNjwU5YEHsO0w== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BC7B3C43458; Sun, 12 Jul 2026 20:21:21 +0000 (UTC) From: Junye Ji via B4 Relay Date: Sun, 12 Jul 2026 13:21:16 -0700 Subject: [PATCH] io_uring/kbuf: free cached iovec only after replacement Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260712-io-uring-kbuf-iovec-lifetime-v1-1-23028d00b6cf@outlook.com> X-B4-Tracking: v=1; b=H4sIAAAAAAAC/x3MQQqDMBAF0KvIrDswRlHwKqULjTP6aY0lURHEu zd0+TbvoqQRmqgrLop6IGENGeWjID/3YVLGmE1OXCNt6Rgr7xFh4vewW9ahnj8w3bAo12a1NL0 M4ivKxTeq4fz3z9d9/wDEzSBTbgAAAA== X-Change-ID: 20260712-io-uring-kbuf-iovec-lifetime-4ff406a0b0c3 To: Jens Axboe Cc: Hao-Yu Yang , io-uring@vger.kernel.org, linux-kernel@vger.kernel.org, Junye Ji X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783887681; l=1694; i=jijunye1@outlook.com; s=junyeji-20260712; h=from:subject:message-id; bh=OUMgENWWWxoEYLpXsl1Dvxz32F/77rmlxtHsMQSj9/Y=; b=TSSzKm2z/AWaYArbGY9qOOLdCpQS9h+8be9MPINfJhHTSCbE8TshWzpdnMC5oTz/CyRHsUlhp DrNq9Q1YNl2D4Q6ekaJSJmmd+ZShhWihtonMqyUwggKJW4opLSwBzea X-Developer-Key: i=jijunye1@outlook.com; a=ed25519; pk=aKIN8hT1V9oSVC83K2q1NNzawUnDaybDxbYJltmwvGE= X-Endpoint-Received: by B4 Relay for jijunye1@outlook.com/junyeji-20260712 with auth_id=865 X-Original-From: Junye Ji Reply-To: jijunye1@outlook.com From: Junye Ji io_ring_buffers_peek() saves the incoming iovec array in org_iovs, then may replace arg->iovs while expanding a provided-buffer bundle. With KBUF_MODE_FREE set, the success path frees arg->iovs instead of org_iovs. It either frees a replacement before the caller uses it or, when no replacement was needed, frees the cache still owned by the request. Cleanup later frees the same cache again. I reproduced the stale read and double free on the no-growth and successful-growth paths with two completions from one multishot receive. The fixed KASAN kernel completed 100 runs of both triggers and both liburing bundle tests without a report. Fixes: cd053d788c3f ("io_uring: fix dangling iovec after provided-buffer bu= ndle grow failure") Assisted-by: Codex-Security:unspecified Signed-off-by: Junye Ji --- I can send the reproducer and full trace/KASAN logs privately if needed. --- io_uring/kbuf.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/io_uring/kbuf.c b/io_uring/kbuf.c index b6b969b55e12..07d81dc7cbe2 100644 --- a/io_uring/kbuf.c +++ b/io_uring/kbuf.c @@ -328,8 +328,8 @@ static int io_ring_buffers_peek(struct io_kiocb *req, s= truct buf_sel_arg *arg, buf =3D io_ring_head_to_buf(br, ++head, bl->mask); } while (--nr_iovs); =20 - if (arg->mode & KBUF_MODE_FREE) - kfree(arg->iovs); + if ((arg->mode & KBUF_MODE_FREE) && arg->iovs !=3D org_iovs) + kfree(org_iovs); =20 if (head =3D=3D tail) req->flags |=3D REQ_F_BL_EMPTY; --- base-commit: 44696aa3a489d2baf58efa61b37833f100072bee change-id: 20260712-io-uring-kbuf-iovec-lifetime-4ff406a0b0c3 Best regards, --=20 Junye Ji