Commit 06381006 authored by Riyan Dhiman's avatar Riyan Dhiman Committed by Zheng Qixing
Browse files

block: fix potential invalid pointer dereference in blk_add_partition

stable inclusion
from stable-v5.10.227
commit 4bc4272e2506941c3f3d4fb8b0c659ee814dcf6f
category: bugifx
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAYPJH
CVE: CVE-2024-47705

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=4bc4272e2506941c3f3d4fb8b0c659ee814dcf6f



--------------------------------

[ Upstream commit 26e197b7f9240a4ac301dd0ad520c0c697c2ea7d ]

The blk_add_partition() function initially used a single if-condition
(IS_ERR(part)) to check for errors when adding a partition. This was
modified to handle the specific case of -ENXIO separately, allowing the
function to proceed without logging the error in this case. However,
this change unintentionally left a path where md_autodetect_dev()
could be called without confirming that part is a valid pointer.

This commit separates the error handling logic by splitting the
initial if-condition, improving code readability and handling specific
error scenarios explicitly. The function now distinguishes the general
error case from -ENXIO without altering the existing behavior of
md_autodetect_dev() calls.

Fixes: b7205307 (block: allow partitions on host aware zone devices)
Signed-off-by: default avatarRiyan Dhiman <riyandhiman14@gmail.com>
Reviewed-by: default avatarChristoph Hellwig <hch@lst.de>
Link: https://lore.kernel.org/r/20240911132954.5874-1-riyandhiman14@gmail.com


Signed-off-by: default avatarJens Axboe <axboe@kernel.dk>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>

Conflicts:
	block/partitions/core.c
[Context inconsistency.]
Signed-off-by: default avatarZheng Qixing <zhengqixing@huawei.com>
parent 6a7ec317
Loading
Loading
Loading
Loading
+5 −3
Original line number Diff line number Diff line
@@ -705,9 +705,11 @@ static bool blk_add_partition(struct gendisk *disk, struct block_device *bdev,

	part = add_partition(disk, p, from, size, state->parts[p].flags,
			     &state->parts[p].info);
	if (IS_ERR(part) && PTR_ERR(part) != -ENXIO) {
	if (IS_ERR(part)) {
		if (PTR_ERR(part) != -ENXIO) {
			printk(KERN_ERR " %s: p%d could not be added: %ld\n",
			       disk->disk_name, p, -PTR_ERR(part));
		}
		return true;
	}