2019-08-07 14:20:42

by Paolo Valente

[permalink] [raw]
Subject: [PATCH BUGFIX 0/2] block, bfq: fix user after free

Hi Jens,
this series contains a pair of fixes for the UAF reported in
[1]. These patches are the result of the testing described in this
Chrome OS issue [2] since Comment 57.

Thanks,
Paolo

[1] https://lkml.org/lkml/2019/7/27/254
[2] https://bugs.chromium.org/p/chromium/issues/detail?id=931295#c57


Paolo Valente (2):
block, bfq: reset last_completed_rq_bfqq if the pointed queue is freed
block, bfq: move update of waker and woken list to queue freeing

block/bfq-iosched.c | 54 ++++++++++++++++++++++++++++++---------------
1 file changed, 36 insertions(+), 18 deletions(-)

--
2.20.1


2019-08-08 13:32:42

by Jens Axboe

[permalink] [raw]
Subject: Re: [PATCH BUGFIX 0/2] block, bfq: fix user after free

On 8/7/19 7:17 AM, Paolo Valente wrote:
> Hi Jens,
> this series contains a pair of fixes for the UAF reported in
> [1]. These patches are the result of the testing described in this
> Chrome OS issue [2] since Comment 57.

Applied, thanks.

--
Jens Axboe

2019-08-13 11:22:25

by Pavel Machek

[permalink] [raw]
Subject: Re: [PATCH BUGFIX 0/2] block, bfq: fix user after free

Hi!

> this series contains a pair of fixes for the UAF reported in
> [1]. These patches are the result of the testing described in this
> Chrome OS issue [2] since Comment 57.

This seems to have solved crashes with chromium on x220 from
"v5.3-rc2: crashes and scrolling in web browser now has audio
feedback" thread.

Best regards,
Pavel

--
DENX Software Engineering GmbH, Managing Director: Wolfgang Denk
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany


Attachments:
(No filename) (508.00 B)
signature.asc (188.00 B)
Digital signature
Download all attachments