Skip to content

Commit 83dbb9a

Browse files
Jaegeuk Kimgregkh
authored andcommitted
f2fs: fix kernel crash due to null io->bio
commit 267c159 upstream. We should return when io->bio is null before doing anything. Otherwise, panic. BUG: kernel NULL pointer dereference, address: 0000000000000010 RIP: 0010:__submit_merged_write_cond+0x164/0x240 [f2fs] Call Trace: <TASK> f2fs_submit_merged_write+0x1d/0x30 [f2fs] commit_checkpoint+0x110/0x1e0 [f2fs] f2fs_write_checkpoint+0x9f7/0xf00 [f2fs] ? __pfx_issue_checkpoint_thread+0x10/0x10 [f2fs] __checkpoint_and_complete_reqs+0x84/0x190 [f2fs] ? preempt_count_add+0x82/0xc0 ? __pfx_issue_checkpoint_thread+0x10/0x10 [f2fs] issue_checkpoint_thread+0x4c/0xf0 [f2fs] ? __pfx_autoremove_wake_function+0x10/0x10 kthread+0xff/0x130 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x2c/0x50 </TASK> Cc: stable@vger.kernel.org # v5.18+ Fixes: 64bf0ee ("f2fs: pass the bio operation to bio_alloc_bioset") Reviewed-by: Chao Yu <chao@kernel.org> Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent de33f12 commit 83dbb9a

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

fs/f2fs/data.c

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -640,6 +640,9 @@ static void __f2fs_submit_merged_write(struct f2fs_sb_info *sbi,
640640

641641
f2fs_down_write(&io->io_rwsem);
642642

643+
if (!io->bio)
644+
goto unlock_out;
645+
643646
/* change META to META_FLUSH in the checkpoint procedure */
644647
if (type >= META_FLUSH) {
645648
io->fio.type = META_FLUSH;
@@ -648,6 +651,7 @@ static void __f2fs_submit_merged_write(struct f2fs_sb_info *sbi,
648651
io->bio->bi_opf |= REQ_PREFLUSH | REQ_FUA;
649652
}
650653
__submit_merged_bio(io);
654+
unlock_out:
651655
f2fs_up_write(&io->io_rwsem);
652656
}
653657

0 commit comments

Comments
 (0)