]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
io_uring/kbuf: free the replaced iovec after a successful grow
authorJaeyeong Lee <iostreampy@proton.me>
Sun, 12 Jul 2026 14:27:12 +0000 (14:27 +0000)
committerJens Axboe <axboe@kernel.dk>
Tue, 14 Jul 2026 18:14:59 +0000 (12:14 -0600)
The provided-buffer validation fix deferred freeing a cached iovec
until validation completed. However, the deferred free uses arg->iovs.
After a grow, that points to the newly allocated array. Without a grow,
it points to the cached array that remains in use.

This leaves the caller with a dangling iovec in both cases and can
result in repeated frees. Only free org_iovs when arg->iovs actually
replaced it.

Fixes: cd053d788c3f ("io_uring: fix dangling iovec after provided-buffer bundle grow failure")
Assisted-by: Codex:gpt-5.3-codex-spark
Signed-off-by: Jaeyeong Lee <iostreampy@proton.me>
Link: https://patch.msgid.link/20260712142612.188695595-iostreampy@proton.me
Signed-off-by: Jens Axboe <axboe@kernel.dk>
io_uring/kbuf.c

index b6b969b55e12241c6998549a72e7c5e454ac35e6..de0129bceaba30a35d69ffa5abe84e78529bac2b 100644 (file)
@@ -328,8 +328,8 @@ static int io_ring_buffers_peek(struct io_kiocb *req, struct buf_sel_arg *arg,
                buf = io_ring_head_to_buf(br, ++head, bl->mask);
        } while (--nr_iovs);
 
-       if (arg->mode & KBUF_MODE_FREE)
-               kfree(arg->iovs);
+       if (arg->iovs != org_iovs && (arg->mode & KBUF_MODE_FREE))
+               kfree(org_iovs);
 
        if (head == tail)
                req->flags |= REQ_F_BL_EMPTY;