Re: [PATCH v1] io_uring: fix dangling iovec after provided-buffer bundle grow failure

Hao-Yu Yang <[email protected]> Tue, 7 Jul 2026 01:34:49 +0800
Newsgroups org.kernel.vger.io-uring,org.kernel.vger.linux-kernel
Message-ID <akvnOaiLOvcHyalG@naup-virtual-machine>
On Mon, Jul 06, 2026 at 11:13:55AM -0600, Jens Axboe wrote:
> On 7/6/26 11:01 AM, Hao-Yu Yang wrote:
> > Sorry, i forgot to cc others mail
> > 
> > I discovered and wrote the PoC myself. Trigger way is
> >  send1: Submit an IORING_OP_SEND request with four valid
> >  provided buffers. The system will allocate and cache an
> >  iovec array (of size 4) for this request and store the
> >  pointer in kmsg->vec.iovec.
> > 
> >  send2: Submit a second send request with 8, and I set
> >  the fourth passed-in address to point to an invalid address.
> >  Now kmsg still hold old iovec, but old iovec object have
> >  been freed.
> > 
> >  So this will lead dangling pointer.
> 
> Side note: please don't top post, linux mailing lists always reply
> under the text for better readability. Top posting turns any kind
> of threaded conversation into both a mess, and it's also wasteful.
> 
> Great thanks! Want to turn this into a liburing test case? Then we can
> include it there as well, and it'd catch both UAF and memory leaks when
> run.
> 
> -- 
> Jens Axboe

How to turn this into a liburing test case? Should this be included in the v2 patch?