+10
−0
Loading
mainline inclusion from mainline-v6.10-rc1 commit d0aac2363549e12cc79b8e285f13d5a9f42fd08e category: bugfix bugzilla: https://gitee.com/src-openeuler/kernel/issues/IA7YKI CVE: CVE-2024-38384 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=d0aac2363549e12cc79b8e285f13d5a9f42fd08e -------------------------------- __blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start is being executed. If WRITE of `->lqueued` is re-ordered with READ of 'bisc->lnode.next' in the loop of __blkcg_rstat_flush(), `next_bisc` can be assigned with one stat instance being added in blk_cgroup_bio_start(), then the local list in __blkcg_rstat_flush() could be corrupted. Fix the issue by adding one barrier. Cc: Tejun Heo <tj@kernel.org> Cc: Waiman Long <longman@redhat.com> Fixes: 3b8cc629 ("blk-cgroup: Optimize blkcg_rstat_flush()") Signed-off-by:Ming Lei <ming.lei@redhat.com> Link: https://lore.kernel.org/r/20240515013157.443672-3-ming.lei@redhat.com Signed-off-by:
Jens Axboe <axboe@kernel.dk> Signed-off-by:
Li Lingfeng <lilingfeng3@huawei.com>