Re: [PATCH v2] scsi: target: Fix NULL se_tpg dereference in target_complete()

Mike Christie <[email protected]> Sat, 25 Jul 2026 15:44:25 -0500
Newsgroups org.kernel.vger.target-devel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-scsi,org.kernel.vger.stable
Message-ID <[email protected]>
On 7/25/26 11:58 AM, Yehyeong Lee wrote:
> The same statement can fault one level earlier: se_sess->se_tpg itself may
> be NULL.  After a session is deregistered, transport_deregister_session()
> clears se_sess->se_tpg, yet the isert receive path can still submit and
> complete a command that references that session, so the backend completion
> runs target_complete() with se_tpg == NULL and dereferences it:
> 
>   Oops: general protection fault, probably for non-canonical address ...
>   KASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087]
>   Workqueue: ib-comp-wq ib_cq_poll_work
>   RIP: 0010:target_complete_cmd_with_sense.part.0+0x17d/0xc90
>   Call Trace:
>    fd_execute_rw
>    __target_execute_cmd
>    iscsit_execute_cmd
>    iscsit_sequence_cmd
>    isert_recv_done
>    __ib_process_cq
>    ib_cq_poll_work
> 
> The exact window in which an isert completion outlives the session
> deregistration has not been pinned down; the guard defends the dereference
> regardless of how the command reaches this point.
> 
I think we need to figure out how we got into this situation because we
can't free the session while it's still in use.