From nobody Tue Sep 29 14:54:44 2026 Received: from mail-pj2-f4.google.com (mail-pj2-f4.google.com [74.125.227.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A174D42050 for ; Fri, 7 Aug 2026 03:15:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.132 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786072557; cv=none; b=N/4AdO2hRzeOxlvTEa6pYcLvmYuHdH8vs2iiHVO9yrUC5n8sUlwCsiwV1YDpiXZWll8WtnEo15qNPtkk+4kDg948LRW0ZX2Ql1yA0y5CexeBntx7j6DF+wLSnsqsaY7ypmBL+wTl9gJ3GjS3QRSCyFaRdbEXHchvPSWDErYwQ50= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786072557; c=relaxed/simple; bh=3A5C3EXvvGEoWJ1l+7sfPmTDNuAFh/3jvfuQgavhu6o=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=K4T8daJM7QQhBlleLP7aZn1PcGmwhQLc5J7JK56SlkcBraelHE5DRVD5ABeL+aplyM75sJsV5qhwLz03e0CryyC7ESf8aRe5YAkqOoeWLdfGBaOvf8gYZZw+wAtMsQHlzYl0oyARVbaN8ndkvuSv13etU0gvHIv+r4jH6dTGY7E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MTXrDPbm; arc=none smtp.client-ip=74.125.227.132 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MTXrDPbm" Received: by mail-pj2-f4.google.com with SMTP id 98e67ed59e1d1-3896ccc93b5so1197764a91.1 for ; Thu, 06 Aug 2026 20:15:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786072555; x=1786677355; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=RCJZpBnqKALyKAEdfIL5xWelEc6Lw3PrSrs6EoGxV8w=; b=MTXrDPbm7z3BBJFr4sa/JaG+xLSwJElgo4+W1fou4zOLNokuQJb7uApJ8zVzmhL6RF Q49mT1MJUliaXTXngc8EVaEUHxAwObOCcCY/r7TmHTh1trtPeVUUkR5cnRAlvY4bM0Ro tEBHi4TpACdmrcvhRPBAvt0yKiIx5LYqvtz8POE4HClnRp35M7xcux2GJqoJipu8/aDN fJmTd0ke5JgUDlbWqQGV+23MRU+q8RA5iIUTzgL5mmhbXUNhytLdGGjaPg3AZRb2j5Lb 55eh32FiUs12ZFwJa11KG8A64Boj0/z/q+WXJKuud4zPL3AyseCvcWtRCqwYG5RU0agK RF5g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786072555; x=1786677355; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=RCJZpBnqKALyKAEdfIL5xWelEc6Lw3PrSrs6EoGxV8w=; b=HNiT8DavuzqsOxwoJcW4IE8I0kMXZVwgn05qTK9Nygcul7Cl+hPmTC2STj83/CrUFe u8ScKYXSHl0PGYoELFrqdH6bpWZIGO8NMu4PJriYUpOpa1UnR0cpCgYhD5BaBQ8fhlXe PyY4TbImD1qnZJ8j23eX2KGyXld4Q69G6CCVqCE+/Wuval0UP+C50SsNdR2HN6/qLIIz gH8ymOZGdCipkasqiD8nkDsptUw20mj1QStiXeWKP6eBxLNX0ZMHR6JZu9pIe6dE/mHb LdLJAt+Rtmag9InBY0FEjobHwzcmlKneVIBJ1fFjtTQxhtZcayQDYBDLcKZ1ifB0k/bT W4hw== X-Forwarded-Encrypted: i=1; AHgh+RoTjkhHYjMPHBuEVbgd/5sCOPtDU8eKNsvrL1RnVNkZwoY7l+DgLjOXxvi6Yq5Y2z0VP8F9LDjpckrUXMQ=@vger.kernel.org X-Gm-Message-State: AOJu0YxROaHWzCuu2vuMZWEDE7XvFlbmqZ8Zb16uo6FGADEZxuT+8WEl gam5B2a9CKiTOLJYCnajnKCNPkz5k6NMDSrPbs8i+xVaiN7NkiqGxkb6 X-Gm-Gg: AR+sD13E24jjQ1Civu4TT6l97RuRj56vVaSudMRffuIIE1Q17I2YPtdy5KK8WbuKMO/ Qw2rhdwv10m+Dxm+1Pbx+hk+E0rnuMWGxt4B9nLhVk3bBPk33v6A2HznwHWvFGwivrFZ1hGpwKj Fx3/w3Vv9pfjOERGNktT5pbfh/eYojw0QhDMK2gFeJYNYitg6Oe+HX3RJhe1jiJiDaVrl22nfGA 1k8GqdcHrtPk7YhUcDcg93PuX1unfFAu3dL7VRP/YUSrfsikzjqoUbjkT0UhAeYOPG1aUaTM/76 zFj2aYE34psmJnqAfqGTdvJ8/4Y5FrHUx/aTmV3geaoovwIs61gimoC9tM1vAZdSSOCcDFxGlUF 9aN6SffzTrXlD4qz0gvexKqMZ92kGvcPwJ7tL+REIyKpvwrjogIiS0xJ0jsR6ma9kjDE5VZ/sYg ySO+MfJHTypYdO1MZXFifXVA5QmvPgMGsT4NW7mfNd2eWK5G3X6vcHuCiW8ge/pGB654PSRLIUJ xkDMmxn9g== X-Received: by 2002:a17:90b:2dc5:b0:38e:ad9d:1151 with SMTP id 98e67ed59e1d1-3909d79f314mr7651334a91.4.1786072554897; Thu, 06 Aug 2026 20:15:54 -0700 (PDT) Received: from J4f-Laptop.localdomain ([2409:8a55:94ec:7c81:f9fc:df1b:ed1e:972c]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-390b30d465csm388060a91.2.2026.08.06.20.15.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 06 Aug 2026 20:15:54 -0700 (PDT) From: Shihuang Liu To: Miklos Szeredi Cc: Zhao Chen , fuse-devel@lists.linux.dev, linux-kernel@vger.kernel.org, Shihuang Liu , stable@vger.kernel.org Subject: [PATCH] fuse: fix use-after-free in fuse_chan_resend() Date: Fri, 7 Aug 2026 11:15:34 +0800 Message-ID: <20260807031534.4362-1-shlomojune6@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" fuse_chan_resend() sets FR_PENDING before acquiring fiq->lock and before the request is actually inserted into fiq->pending. A concurrent cancellation path may therefore observe FR_PENDING, incorrectly assume that the request belongs to the lock-protected pending list, remove it, and drop the queue-held reference. The waiting thread may then release the final reference and free the request while fuse_chan_resend() still holds and accesses it, resulting in a use-after-free. The following is a simple race scenario: CPU1 CPUx fuse_chan_resend() move req from processing to stack-local to_queue set FR_PENDING request receives SIGKILL fuse_remove_pending_req() sees FR_PENDING set list_del(&req->list) drop queue reference request thread drops its reference refcount reaches zero req is freed access struct fuse_req lead to use-after-free A FUSE request being resent concurrently with fatal-signal cancellation can trigger a slab use-after-free. [ 27.327266] =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D [ 27.329157] BUG: KASAN: slab-use-after-free in fuse_chan_resend+0x29c/0x= 7c0 [ 27.330554] Write of size 8 at addr ffff8880079975a0 by task exploit/1711 Move the FR_PENDING publication and the other resend state updates under fiq->lock, in the same critical section that requeues the requests on fiq->pending. This prevents cancellation from observing FR_PENDING while the request is still on the private to_queue list. Fixes: 760eac73f9f6 ("fuse: Introduce a new notification type for resend pe= nding requests") Cc: stable@vger.kernel.org Signed-off-by: Shihuang Liu --- fs/fuse/dev.c | 16 ++++++---------- 1 file changed, 6 insertions(+), 10 deletions(-) diff --git a/fs/fuse/dev.c b/fs/fuse/dev.c index 5763a7cd3b37..e54567bd247e 100644 --- a/fs/fuse/dev.c +++ b/fs/fuse/dev.c @@ -1760,7 +1760,7 @@ static ssize_t fuse_dev_splice_read(struct file *in, = loff_t *ppos, void fuse_chan_resend(struct fuse_chan *fch) { struct fuse_dev *fud; - struct fuse_req *req, *next; + struct fuse_req *req; struct fuse_iqueue *fiq =3D &fch->iq; LIST_HEAD(to_queue); unsigned int i; @@ -1781,18 +1781,9 @@ void fuse_chan_resend(struct fuse_chan *fch) } spin_unlock(&fch->lock); =20 - list_for_each_entry_safe(req, next, &to_queue, list) { - set_bit(FR_PENDING, &req->flags); - clear_bit(FR_SENT, &req->flags); - /* mark the request as resend request */ - req->in.h.unique |=3D FUSE_UNIQUE_RESEND; - } - spin_lock(&fiq->lock); if (!fiq->connected) { spin_unlock(&fiq->lock); - list_for_each_entry(req, &to_queue, list) - clear_bit(FR_PENDING, &req->flags); fuse_dev_end_requests(&to_queue); return; } @@ -1801,6 +1792,11 @@ void fuse_chan_resend(struct fuse_chan *fch) * intr_entry on fiq->interrupts after the request is re-queued. */ list_for_each_entry(req, &to_queue, list) { + set_bit(FR_PENDING, &req->flags); + clear_bit(FR_SENT, &req->flags); + /* mark the request as resend request */ + req->in.h.unique |=3D FUSE_UNIQUE_RESEND; + if (test_bit(FR_INTERRUPTED, &req->flags)) list_del_init(&req->intr_entry); } --=20 2.43.0