Commit 95bc57bd authored by Li Nan's avatar Li Nan
Browse files

md: fix kmemleak of rdev->serial

mainline inclusion
from mainline-v6.9-rc1
commit 6cf350658736681b9d6b0b6e58c5c76b235bb4c4
category: bugfix
bugzilla: 189820, https://gitee.com/src-openeuler/kernel/issues/I9HKBT
CVE: CVE-2024-26900

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6cf350658736681b9d6b0b6e58c5c76b235bb4c4



--------------------------------

If kobject_add() is fail in bind_rdev_to_array(), 'rdev->serial' will be
alloc not be freed, and kmemleak occurs.

unreferenced object 0xffff88815a350000 (size 49152):
  comm "mdadm", pid 789, jiffies 4294716910
  hex dump (first 32 bytes):
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace (crc f773277a):
    [<0000000058b0a453>] kmemleak_alloc+0x61/0xe0
    [<00000000366adf14>] __kmalloc_large_node+0x15e/0x270
    [<000000002e82961b>] __kmalloc_node.cold+0x11/0x7f
    [<00000000f206d60a>] kvmalloc_node+0x74/0x150
    [<0000000034bf3363>] rdev_init_serial+0x67/0x170
    [<0000000010e08fe9>] mddev_create_serial_pool+0x62/0x220
    [<00000000c3837bf0>] bind_rdev_to_array+0x2af/0x630
    [<0000000073c28560>] md_add_new_disk+0x400/0x9f0
    [<00000000770e30ff>] md_ioctl+0x15bf/0x1c10
    [<000000006cfab718>] blkdev_ioctl+0x191/0x3f0
    [<0000000085086a11>] vfs_ioctl+0x22/0x60
    [<0000000018b656fe>] __x64_sys_ioctl+0xba/0xe0
    [<00000000e54e675e>] do_syscall_64+0x71/0x150
    [<000000008b0ad622>] entry_SYSCALL_64_after_hwframe+0x6c/0x74

Fixes: 963c555e ("md: introduce mddev_create/destroy_wb_pool for the change of member device")
Signed-off-by: default avatarLi Nan <linan122@huawei.com>
Signed-off-by: default avatarSong Liu <song@kernel.org>
Link: https://lore.kernel.org/r/20240208085556.2412922-1-linan666@huaweicloud.com



Conflict:
	drivers/md/md.c
	1. Mainline commit b4128c00a653 ("md: cleanup mddev_create/
	destroy_serial_pool()") removed the third param of
	mddev_destroy_serial_pool().
	2. OLK commit 3bb76c49199e ("[Huawei] md: fix sysfs duplicate
	file while adding rdev") changed context.
Signed-off-by: default avatarLi Nan <linan122@huawei.com>
parent 1472570a
Loading
Loading
Loading
Loading
+1 −0
Original line number Diff line number Diff line
@@ -2496,6 +2496,7 @@ static int bind_rdev_to_array(struct md_rdev *rdev, struct mddev *mddev)
 fail:
	pr_warn("md: failed to register %s for %s\n",
		b, mdname(mddev));
	mddev_destroy_serial_pool(mddev, rdev, false);
	return err;
}