• F
    Btrfs: fix use-after-free during inode eviction · 421f0922
    Filipe Manana 提交于
    At inode.c:evict_inode_truncate_pages(), when we iterate over the
    inode's extent states, we access an extent state record's "state" field
    after we unlocked the inode's io tree lock. This can lead to a
    use-after-free issue because after we unlock the io tree that extent
    state record might have been freed due to being merged into another
    adjacent extent state record (a previous inflight bio for a read
    operation finished in the meanwhile which unlocked a range in the io
    tree and cause a merge of extent state records, as explained in the
    comment before the while loop added in commit 6ca07097 ("Btrfs: fix
    hang during inode eviction due to concurrent readahead")).
    
    Fix this by keeping a copy of the extent state's flags in a local
    variable and using it after unlocking the io tree.
    
    Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=201189
    Fixes: b9d0b389 ("btrfs: Add handler for invalidate page")
    CC: stable@vger.kernel.org # 4.4+
    Reviewed-by: NQu Wenruo <wqu@suse.com>
    Signed-off-by: NFilipe Manana <fdmanana@suse.com>
    Reviewed-by: NDavid Sterba <dsterba@suse.com>
    Signed-off-by: NDavid Sterba <dsterba@suse.com>
    421f0922
inode.c 284.5 KB