From nobody Fri Oct 2 13:03:29 2026 Received: from mail-qk1-f175.google.com (mail-qk1-f175.google.com [209.85.222.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 11CB6418A36 for ; Fri, 31 Jul 2026 11:00:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785495617; cv=none; b=Mg5OSICSQ4cBJQWPOsD6VZ3C+lzJO7N/Q94eai2GzIb3wdqHiQjUbIca6GoXvwq5ATmBifTIvar/DBpklBCrlY9cYVhfJEJFPOGoj2yC8IvdrWSDDFGr7MMtopOCu8HNMT6a6ianf61Kfz2d68doRCT3qptheasrrZmKuvaU1Iw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785495617; c=relaxed/simple; bh=MPBCkx2e0hfZDwu6Ma3IcCnh1XLX7aXMhGljF2ciOho=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=R1kf8Kwsv73rW01ARsqZg6OiAl0gaArLgraDLbA17kiDcsVhFQVk18Q+YAQs9vY4MlgJhyCeBQm2CF+Mjs/dXTd+7o9Vw/w71T1kWZPCTfAYMuwHF/B1JTj38sJATi7HiGNlRf9+BSgr2oH5diIGDqtVx3oPYi3+iBTNL2D0Wsc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=VYig+NIU; arc=none smtp.client-ip=209.85.222.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="VYig+NIU" Received: by mail-qk1-f175.google.com with SMTP id af79cd13be357-930fad20240so40495285a.0 for ; Fri, 31 Jul 2026 04:00:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785495611; x=1786100411; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=E77D45gvvB/Gc6kYtlWwwpZQAm6W1TGjK8TmAiQ7i4U=; b=VYig+NIU6X8gYHtluXZvOkbXxo4O4tmvBdCefqrnzTm57JDzF/vyhyfDYoIXrD0F2Y N3HpHjeTw2wBAXuQjeiZa3OsJNLtAo+aa7MScWMNj0A/SQSs1twgyT+Uqp0pOZHPgDxu 3SUFchR+DL3G93xHsi0KzIcHLFqYp5Ie4hW/swv4Pik72GNfI5O5HUAzHtVW6Mus5JDj BoGFORIzDJHcnHhLUEJKEitHH4SbLZlp9PlBn/7ZiOvw3NiXNGFRHHpBlf5jrD6I6XRw iL/RdMxdxYbwXAZrkfCT7fKV+bBCmmvQyhWHHAfXQnL/KiSgniJRyTGuOUnJEOvCQueh ShSw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785495611; x=1786100411; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=E77D45gvvB/Gc6kYtlWwwpZQAm6W1TGjK8TmAiQ7i4U=; b=sIIfIUres3VCF2tWxtgDg9obVdpn759K7vQKIB38aZhfFI1lgpHQM+esV6Oh3lI2tj /dWgt51QfwExYYgVbbyAQHPhV9zHHaa9WyjTZ54NTkcsJaUMLjOxPsndv/715wvO57y1 6OZP53xBtVlp8I35ZHKiKV/N9c9Wiyrpi/btcl4WYoAqDsHY7tyfQT8vaFEafk2k3SGZ EUzdZItS+K7WtGxSRJD2dygGUcGCSGOyqf9Uq/b3cO07oR1Ng9W3FkFnhv9eusfZT7nX 78hZ4n7U2pLRKPRfR4xhkOKEIUtWysDvFFfTDko53Pz9omVYfF7mwrhdL1eSGknisHrp /AxQ== X-Forwarded-Encrypted: i=1; AHgh+Rpl7twu13nukmVTPC/jFv7JNHGcMpAY87P2JEO2G+8LKfiDfSIP8E5RBp2h2Vo09Tyk48NShSxxIDf3ip8=@vger.kernel.org X-Gm-Message-State: AOJu0YzEannnlAomDJbbBcJYgW5wDm1ymD5JutW0ma835fvWBEFMmjc6 OBQ/XXtbwDgszYvyK+K+eRNJISu2xoGWF6EK8A3WRRnHaCk+Y3pHdAzOySs1/6W/U2s= X-Gm-Gg: AR+sD10VRUBSElKpPSOxM+0n72iXKKPtbrjfi2nRM+tZezvoBdLzmc4TFUTvvJR2fOF z8/tDxeJojXiXONhh62mOuRTBccRq8lXkH+nrye/8MrD4U1fZjRU1CQAMoQk+81HchfmMxJmTbF DehgtITUXDz8arLLrRYCTOVeGzydvqBMSzzJa4eveOs/d34FsBXw8schtZLLVhNt4yXyGj6FHmf Y4ikGgqoRhLhyzqi5laipzA5y62f+2qR4ZzdVhtEINJq4+s87fMOHBBecCQ3qOHBpaQ49C4Jxqv 60BR7RQT60bf8gBRoQ8TaQ+JxMyqwWZ5QJoKqqFL5k5FlYtzm8CCaSbmmkzXZEHDvA9Ek2RfcE5 2jgrrH2U1yTuRRQ9k6CaFHlOzFoQHWJOqrjIAr/KOdHl5j/orSqbyykrSuRq73zSEC09kgFGgcU JQSGuESC9ByWOJXq+BhEVprpsSMB6PcLmHX/1KjFks+2dQI1M056WJzg5/ZI8JRxM/Xw== X-Received: by 2002:a05:620a:711a:b0:92e:46e5:8f12 with SMTP id af79cd13be357-934967bdf8emr178039385a.30.1785495611077; Fri, 31 Jul 2026 04:00:11 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-908435b58e0sm7686826d6.31.2026.07.31.04.00.10 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 04:00:10 -0700 (PDT) From: David Lee To: shaggy@kernel.org Cc: David Lee , Kyle Zeng , Dominik 'Disconnect3d' Czarnota , jfs-discussion@lists.sourceforge.net, linux-kernel@vger.kernel.org Subject: [PATCH] jfs: pin metapage during synchronous writeback Date: Fri, 31 Jul 2026 11:00:06 +0000 Message-ID: <20260731110008.543282-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" release_metapage() decrements mp->count from one to zero but keeps the struct metapage pointer in its local variable mp. For synchronous writeback, release_metapage() calls metapage_write_one(), which in turn calls metapage_write_folio(). metapage_write_folio() clears META_dirty, submits the I/O, and this unlocks the folio while synchronous I/O is in progress. After writeback completes, kswapd can acquire the folio lock before release_metapage(). metapage_release_folio() then sees mp->count =3D=3D 0 and META_dirty clear, removes mp from the folio, and frees the struct metapage. release_metapage() subsequently reacquires the folio lock and passes its now-dangling mp pointer to drop_metapage(), which does an use-after-free read of mp->count. Increment mp->count before calling metapage_write_one(), and decrement it only after release_metapage() has reacquired the folio lock. The nonzero count makes metapage_release_folio() leave the struct metapage allocated throughout the unlocked writeback interval. Once release_metapage() holds the folio lock again, it can drop the temporary reference and safely finish using mp. Bug found and triaged by OpenAI Security Research and=20 validated by Trail of Bits. Assisted-by: Codex:gpt-5.6-sol gpt-5.5-cyber Signed-off-by: Kyle Zeng --- Trail of Bits has a reproducer for this bug that triggers a KASAN use-after= -free and can share if needed. fs/jfs/jfs_metapage.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/fs/jfs/jfs_metapage.c b/fs/jfs/jfs_metapage.c index 41fe12e641ce..d1962a44125a 100644 --- a/fs/jfs/jfs_metapage.c +++ b/fs/jfs/jfs_metapage.c @@ -882,9 +882,12 @@ void release_metapage(struct metapage * mp) folio_mark_dirty(folio); if (test_bit(META_sync, &mp->flag)) { clear_bit(META_sync, &mp->flag); + /* Pin mp while metapage_write_one() drops the folio lock. */ + mp->count++; if (metapage_write_one(folio)) jfs_error(mp->sb, "metapage_write_one() failed\n"); folio_lock(folio); + mp->count--; } } else if (mp->lsn) /* discard_metapage doesn't remove it */ remove_from_logsync(mp); --=20 2.53.0