Forwarded: [PATCH] iommufd: Fix NULL deref of area->pages in ioas_change_process

syzbot <[email protected]>
Newsgroups org.kernel.vger.linux-kernel
Message-ID <[email protected]>
For archival purposes, forwarding an incoming command email to
[email protected], [email protected].

***

Subject: [PATCH] iommufd: Fix NULL deref of area->pages in ioas_change_process
Author: [email protected]

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master

Areas are inserted into the area_itree before area->pages is assigned,
so an area with a NULL pages pointer is briefly visible to readers.
iommufd_ioas_change_process() walks every area and dereferences
area->pages unconditionally, which oopses when racing with a
concurrent IOMMU_IOAS_MAP_FILE.

Reject the racing case with -EBUSY, matching how
iopt_unmap_iova_range() handles the same window. Checking in the first
loop covers the whole function since all iova_rwsems are held for
write across the call.

Reported-by: [email protected]
Closes: https://syzkaller.appspot.com/bug?extid=48637757323884de77a2
Signed-off-by: Deepanshu Kartikey <[email protected]>
---
 drivers/iommu/iommufd/ioas.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/iommu/iommufd/ioas.c b/drivers/iommu/iommufd/ioas.c
index fed06c2b728e..71bffece84b5 100644
--- a/drivers/iommu/iommufd/ioas.c
+++ b/drivers/iommu/iommufd/ioas.c
@@ -535,6 +535,10 @@ int iommufd_ioas_change_process(struct iommufd_ucmd *ucmd)
 		return rc;
 
 	for_each_ioas_area(&ioas_list, index, ioas, area)  {
+		if (!area->pages) {
+			rc = -EBUSY;
+			goto out;
+		}
 		if (area->pages->type != IOPT_ADDRESS_FILE) {
 			rc = -EINVAL;
 			goto out;
-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.