mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 09:20:13 -04:00
fuse: copy request headers via a stack buffer for io-uring
The fuse-io-uring transport copies req->in.h out to the ring in
fuse_uring_copy_to_ring() and req->out.h back in fuse_uring_commit().
Both headers live inside the fuse_request slab object, whose cache
(fuse_req_cachep) is created without a usercopy whitelist, so copying
them directly to/from userspace trips CONFIG_HARDENED_USERCOPY and
panics:
usercopy: Kernel memory exposure attempt detected from SLUB object
'fuse_request' (offset 56, size 40)!
kernel BUG at mm/usercopy.c:102!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:usercopy_abort (mm/usercopy.c:90)
Call Trace:
__check_heap_object (mm/slub.c:8268)
__check_object_size (mm/usercopy.c:197 mm/usercopy.c:258 mm/usercopy.c:223)
copy_header_to_ring (fs/fuse/dev_uring.c:618)
fuse_uring_prepare_send (fs/fuse/dev_uring.c:776 fs/fuse/dev_uring.c:785)
fuse_uring_send_in_task (fs/fuse/dev_uring.c:1306)
tctx_task_work_run (io_uring/tw.c:96)
task_work_run (kernel/task_work.c:233)
io_run_task_work (io_uring/tw.h:84)
io_cqring_wait (io_uring/wait.c:278)
__do_sys_io_uring_enter (io_uring/io_uring.c:2685)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Bounce both headers through an on-stack copy so the usercopy touches
stack memory, not the slab object.
Fixes: c090c8abae ("fuse: Add io-uring sqe commit and fetch support")
Cc: stable@vger.kernel.org
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: Bernd Schubert <bernd@bsbernd.com>
Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
This commit is contained in:
committed by
Miklos Szeredi
parent
4332cf75e4
commit
fd10f40af3
@@ -922,6 +922,7 @@ static int fuse_uring_copy_to_ring(struct fuse_ring_ent *ent,
|
||||
unsigned int issue_flags)
|
||||
{
|
||||
struct fuse_ring_queue *queue = ent->queue;
|
||||
struct fuse_in_header in_header;
|
||||
int err;
|
||||
|
||||
err = -EIO;
|
||||
@@ -943,8 +944,9 @@ static int fuse_uring_copy_to_ring(struct fuse_ring_ent *ent,
|
||||
}
|
||||
|
||||
/* copy fuse_in_header */
|
||||
return copy_header_to_ring(ent, FUSE_URING_HEADER_IN_OUT, &req->in.h,
|
||||
sizeof(req->in.h));
|
||||
in_header = req->in.h;
|
||||
return copy_header_to_ring(ent, FUSE_URING_HEADER_IN_OUT, &in_header,
|
||||
sizeof(in_header));
|
||||
}
|
||||
|
||||
static bool fuse_uring_req_has_copyable_payload(struct fuse_ring_ent *ent,
|
||||
@@ -1151,11 +1153,13 @@ static struct fuse_req *fuse_uring_ent_assign_req(struct fuse_ring_ent *ent)
|
||||
static void fuse_uring_commit(struct fuse_ring_ent *ent, struct fuse_req *req,
|
||||
unsigned int issue_flags)
|
||||
{
|
||||
struct fuse_out_header out_header;
|
||||
ssize_t err = -EFAULT;
|
||||
|
||||
if (copy_header_from_ring(ent, FUSE_URING_HEADER_IN_OUT, &req->out.h,
|
||||
sizeof(req->out.h)))
|
||||
if (copy_header_from_ring(ent, FUSE_URING_HEADER_IN_OUT, &out_header,
|
||||
sizeof(out_header)))
|
||||
goto out;
|
||||
req->out.h = out_header;
|
||||
|
||||
err = fuse_uring_out_header_has_err(&req->out.h, req);
|
||||
if (err) {
|
||||
|
||||
Reference in New Issue
Block a user