In the Linux kernel, the following vulnerability has been resolved:
block, bfq: fix bfqq uaf in bfqlimitdepth()
Set new allocated bfqq to bic or remove freed bfqq from bic are both protected by bfqd->lock, however bfqlimitdepth() is deferencing bfqq from bic without the lock, this can lead to UAF if the io_context is shared by multiple tasks.
For example, test bfq with io_uring can trigger following UAF in v6.6:
================================================================== BUG: KASAN: slab-use-after-free in bfqq_group+0x15/0x50
Call Trace: <TASK> dumpstacklvl+0x47/0x80 printaddressdescription.constprop.0+0x66/0x300 printreport+0x3e/0x70 kasanreport+0xb4/0xf0 bfqqgroup+0x15/0x50 bfqqrequestoverlimit+0x130/0x9a0 bfqlimitdepth+0x1b5/0x480 _blkmqallocrequests+0x2b5/0xa00 blkmqgetnewrequests+0x11d/0x1d0 blkmqsubmitbio+0x286/0xb00 submitbionoacctnocheck+0x331/0x400 _blockwritefullfolio+0x3d0/0x640 writepagecb+0x3b/0xc0 writecachepages+0x254/0x6c0 writecachepages+0x254/0x6c0 dowritepages+0x192/0x310 filemapfdatawritewbc+0x95/0xc0 _filemapfdatawriterange+0x99/0xd0 filemapwriteandwaitrange.part.0+0x4d/0xa0 blkdevreaditer+0xef/0x1e0 ioread+0x1b6/0x8a0 ioissuesqe+0x87/0x300 iowqsubmitwork+0xeb/0x390 ioworkerhandlework+0x24d/0x550 iowqworker+0x27f/0x6c0 retfromfork_asm+0x1b/0x30 </TASK>
Allocated by task 808602: kasansavestack+0x1e/0x40 kasansettrack+0x21/0x30 _kasanslaballoc+0x83/0x90 kmemcacheallocnode+0x1b1/0x6d0 bfqgetqueue+0x138/0xfa0 bfqgetbfqqhandlesplit+0xe3/0x2c0 bfqinitrq+0x196/0xbb0 bfqinsertrequest.isra.0+0xb5/0x480 bfqinsertrequests+0x156/0x180 blkmqinsertrequest+0x15d/0x440 blkmqsubmitbio+0x8a4/0xb00 submitbionoacctnocheck+0x331/0x400 _blkdevdirectIOasync+0x2dd/0x330 blkdevwriteiter+0x39a/0x450 iowrite+0x22a/0x840 ioissuesqe+0x87/0x300 iowqsubmitwork+0xeb/0x390 ioworkerhandlework+0x24d/0x550 iowqworker+0x27f/0x6c0 retfromfork+0x2d/0x50 retfromfork_asm+0x1b/0x30
Freed by task 808589: kasansavestack+0x1e/0x40 kasansettrack+0x21/0x30 kasansavefreeinfo+0x27/0x40 _kasanslabfree+0x126/0x1b0 kmemcachefree+0x10c/0x750 bfqputqueue+0x2dd/0x770 _bfqinsertrequest.isra.0+0x155/0x7a0 bfqinsertrequest.isra.0+0x122/0x480 bfqinsertrequests+0x156/0x180 blkmqdispatchpluglist+0x528/0x7e0 blkmqflushpluglist.part.0+0xe5/0x590 _blkflushplug+0x3b/0x90 blkfinishplug+0x40/0x60 dowritepages+0x19d/0x310 filemapfdatawritewbc+0x95/0xc0 _filemapfdatawriterange+0x99/0xd0 filemapwriteandwaitrange.part.0+0x4d/0xa0 blkdevreaditer+0xef/0x1e0 ioread+0x1b6/0x8a0 ioissuesqe+0x87/0x300 iowqsubmitwork+0xeb/0x390 ioworkerhandlework+0x24d/0x550 iowqworker+0x27f/0x6c0 retfromfork+0x2d/0x50 retfromforkasm+0x1b/0x30
Fix the problem by protecting bictobfqq() with bfqd->lock.
[
{
"digest": {
"length": 72.0,
"function_hash": "33274676690557014236160525529778209973"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@906cdbdd3b018ff69cc830173bce277a847d4fdc",
"id": "CVE-2024-53166-07a87e14"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327102420969696287530467343280555616400",
"132450317487361641981010144909407754376",
"316855361068090986600376263250713843760",
"329753758501034226787444878940095545473",
"58664612821438004015617143659953921676",
"115092116133989893136646140124551959674",
"300935651631959984530839628756161216191",
"286309170369632770054057909477786211022",
"301060344272691984823410434865810310036",
"145893812671617020640907867530768016628",
"50229270133375263841429452693619638691",
"277816918567344843658864729455919133303",
"216106634216588420319240189056731427584",
"58164855105838586367516097264006399872",
"304653411831489304201658913663626523644",
"182851935746149654375200561093326966372",
"140050095233915681096044870326031976153",
"47868250479704598889277253125910286717",
"207415883249794483475009545600833491715",
"241530244306861137565841480923054613603",
"61141103776555754343116379621341993104",
"83162401134601255478298896041255876991",
"249470609575255593227567711251600878878",
"56290521573828687836757978268154317906",
"33957044392179972745699148443371601018",
"109124045047846459229368498556152651146",
"237030083602963831921262676072753002696",
"99305640848605302243516860730333968960",
"12029186118022313304452207755051730795",
"132597012951185413046106254931253609168",
"285218170652143975551295133512853744723",
"231823921583961401672833861517966317297"
]
},
"target": {
"file": "block/bfq-iosched.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e8b8344de3980709080d86c157d24e7de07d70ad",
"id": "CVE-2024-53166-2095e63e"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327102420969696287530467343280555616400",
"132450317487361641981010144909407754376",
"316855361068090986600376263250713843760",
"329753758501034226787444878940095545473",
"58664612821438004015617143659953921676",
"115092116133989893136646140124551959674",
"300935651631959984530839628756161216191",
"286309170369632770054057909477786211022",
"301060344272691984823410434865810310036",
"145893812671617020640907867530768016628",
"50229270133375263841429452693619638691",
"277816918567344843658864729455919133303",
"216106634216588420319240189056731427584",
"58164855105838586367516097264006399872",
"304653411831489304201658913663626523644",
"182851935746149654375200561093326966372",
"140050095233915681096044870326031976153",
"47868250479704598889277253125910286717",
"207415883249794483475009545600833491715",
"241530244306861137565841480923054613603",
"61141103776555754343116379621341993104",
"83162401134601255478298896041255876991",
"249470609575255593227567711251600878878",
"56290521573828687836757978268154317906",
"33957044392179972745699148443371601018",
"109124045047846459229368498556152651146",
"237030083602963831921262676072753002696",
"99305640848605302243516860730333968960",
"12029186118022313304452207755051730795",
"132597012951185413046106254931253609168",
"285218170652143975551295133512853744723",
"231823921583961401672833861517966317297"
]
},
"target": {
"file": "block/bfq-iosched.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ada4ca5fd5a9d5212f28164d49a4885951c979c9",
"id": "CVE-2024-53166-3a41446b"
},
{
"digest": {
"length": 781.0,
"function_hash": "162189108018452180516458713097068844316"
},
"target": {
"function": "bfq_limit_depth",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@906cdbdd3b018ff69cc830173bce277a847d4fdc",
"id": "CVE-2024-53166-3a67799e"
},
{
"digest": {
"length": 72.0,
"function_hash": "33274676690557014236160525529778209973"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e8b8344de3980709080d86c157d24e7de07d70ad",
"id": "CVE-2024-53166-625a1a94"
},
{
"digest": {
"length": 1456.0,
"function_hash": "81176366056673218420843029437113252113"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ada4ca5fd5a9d5212f28164d49a4885951c979c9",
"id": "CVE-2024-53166-6830de11"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327102420969696287530467343280555616400",
"132450317487361641981010144909407754376",
"316855361068090986600376263250713843760",
"329753758501034226787444878940095545473",
"58664612821438004015617143659953921676",
"115092116133989893136646140124551959674",
"300935651631959984530839628756161216191",
"286309170369632770054057909477786211022",
"301060344272691984823410434865810310036",
"145893812671617020640907867530768016628",
"50229270133375263841429452693619638691",
"277816918567344843658864729455919133303",
"216106634216588420319240189056731427584",
"58164855105838586367516097264006399872",
"304653411831489304201658913663626523644",
"182851935746149654375200561093326966372",
"140050095233915681096044870326031976153",
"47868250479704598889277253125910286717",
"207415883249794483475009545600833491715",
"241530244306861137565841480923054613603",
"61141103776555754343116379621341993104",
"83162401134601255478298896041255876991",
"249470609575255593227567711251600878878",
"56290521573828687836757978268154317906",
"33957044392179972745699148443371601018",
"109124045047846459229368498556152651146",
"237030083602963831921262676072753002696",
"99305640848605302243516860730333968960",
"12029186118022313304452207755051730795",
"132597012951185413046106254931253609168",
"285218170652143975551295133512853744723",
"231823921583961401672833861517966317297"
]
},
"target": {
"file": "block/bfq-iosched.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@906cdbdd3b018ff69cc830173bce277a847d4fdc",
"id": "CVE-2024-53166-75ec1fc9"
},
{
"digest": {
"length": 72.0,
"function_hash": "33274676690557014236160525529778209973"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@01a853faaeaf3379ccf358ade582b1d28752126e",
"id": "CVE-2024-53166-779414a5"
},
{
"digest": {
"length": 1456.0,
"function_hash": "81176366056673218420843029437113252113"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e8b8344de3980709080d86c157d24e7de07d70ad",
"id": "CVE-2024-53166-77d45064"
},
{
"digest": {
"length": 781.0,
"function_hash": "162189108018452180516458713097068844316"
},
"target": {
"function": "bfq_limit_depth",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dcaa738afde55085ac6056252e319479cf23cde2",
"id": "CVE-2024-53166-843c1f4b"
},
{
"digest": {
"length": 72.0,
"function_hash": "33274676690557014236160525529778209973"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dcaa738afde55085ac6056252e319479cf23cde2",
"id": "CVE-2024-53166-a4b25a84"
},
{
"digest": {
"length": 1456.0,
"function_hash": "81176366056673218420843029437113252113"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dcaa738afde55085ac6056252e319479cf23cde2",
"id": "CVE-2024-53166-a5897d2d"
},
{
"digest": {
"length": 72.0,
"function_hash": "33274676690557014236160525529778209973"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ada4ca5fd5a9d5212f28164d49a4885951c979c9",
"id": "CVE-2024-53166-af64b6f1"
},
{
"digest": {
"length": 781.0,
"function_hash": "162189108018452180516458713097068844316"
},
"target": {
"function": "bfq_limit_depth",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@01a853faaeaf3379ccf358ade582b1d28752126e",
"id": "CVE-2024-53166-bb8b9965"
},
{
"digest": {
"length": 1456.0,
"function_hash": "81176366056673218420843029437113252113"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@01a853faaeaf3379ccf358ade582b1d28752126e",
"id": "CVE-2024-53166-d085a1d0"
},
{
"digest": {
"length": 1456.0,
"function_hash": "81176366056673218420843029437113252113"
},
"target": {
"function": "bfqq_request_over_limit",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@906cdbdd3b018ff69cc830173bce277a847d4fdc",
"id": "CVE-2024-53166-d0da25ee"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327102420969696287530467343280555616400",
"132450317487361641981010144909407754376",
"316855361068090986600376263250713843760",
"329753758501034226787444878940095545473",
"58664612821438004015617143659953921676",
"115092116133989893136646140124551959674",
"300935651631959984530839628756161216191",
"286309170369632770054057909477786211022",
"301060344272691984823410434865810310036",
"145893812671617020640907867530768016628",
"50229270133375263841429452693619638691",
"277816918567344843658864729455919133303",
"216106634216588420319240189056731427584",
"58164855105838586367516097264006399872",
"304653411831489304201658913663626523644",
"182851935746149654375200561093326966372",
"140050095233915681096044870326031976153",
"47868250479704598889277253125910286717",
"207415883249794483475009545600833491715",
"241530244306861137565841480923054613603",
"61141103776555754343116379621341993104",
"83162401134601255478298896041255876991",
"249470609575255593227567711251600878878",
"56290521573828687836757978268154317906",
"33957044392179972745699148443371601018",
"109124045047846459229368498556152651146",
"237030083602963831921262676072753002696",
"99305640848605302243516860730333968960",
"12029186118022313304452207755051730795",
"132597012951185413046106254931253609168",
"285218170652143975551295133512853744723",
"231823921583961401672833861517966317297"
]
},
"target": {
"file": "block/bfq-iosched.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@01a853faaeaf3379ccf358ade582b1d28752126e",
"id": "CVE-2024-53166-d17bbcbc"
},
{
"digest": {
"length": 781.0,
"function_hash": "162189108018452180516458713097068844316"
},
"target": {
"function": "bfq_limit_depth",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ada4ca5fd5a9d5212f28164d49a4885951c979c9",
"id": "CVE-2024-53166-d23cf9dc"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327102420969696287530467343280555616400",
"132450317487361641981010144909407754376",
"316855361068090986600376263250713843760",
"329753758501034226787444878940095545473",
"58664612821438004015617143659953921676",
"115092116133989893136646140124551959674",
"300935651631959984530839628756161216191",
"286309170369632770054057909477786211022",
"301060344272691984823410434865810310036",
"145893812671617020640907867530768016628",
"50229270133375263841429452693619638691",
"277816918567344843658864729455919133303",
"216106634216588420319240189056731427584",
"58164855105838586367516097264006399872",
"304653411831489304201658913663626523644",
"182851935746149654375200561093326966372",
"140050095233915681096044870326031976153",
"47868250479704598889277253125910286717",
"207415883249794483475009545600833491715",
"241530244306861137565841480923054613603",
"61141103776555754343116379621341993104",
"83162401134601255478298896041255876991",
"249470609575255593227567711251600878878",
"56290521573828687836757978268154317906",
"33957044392179972745699148443371601018",
"109124045047846459229368498556152651146",
"237030083602963831921262676072753002696",
"99305640848605302243516860730333968960",
"12029186118022313304452207755051730795",
"132597012951185413046106254931253609168",
"285218170652143975551295133512853744723",
"231823921583961401672833861517966317297"
]
},
"target": {
"file": "block/bfq-iosched.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dcaa738afde55085ac6056252e319479cf23cde2",
"id": "CVE-2024-53166-d43470f8"
},
{
"digest": {
"length": 781.0,
"function_hash": "162189108018452180516458713097068844316"
},
"target": {
"function": "bfq_limit_depth",
"file": "block/bfq-iosched.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e8b8344de3980709080d86c157d24e7de07d70ad",
"id": "CVE-2024-53166-e7e37744"
}
]