From: Greg Kroah-Hartman Date: Mon, 20 Jul 2026 13:50:08 +0000 (+0200) Subject: 5.15-stable patches X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=9955a1501d19fbc4c22b3247564d199d4ad7e11d;p=thirdparty%2Fkernel%2Fstable-queue.git 5.15-stable patches added patches: jbd2-fix-integer-underflow-in-jbd2_journal_initialize_fast_commit.patch lockd-plug-nlm_file-leak-when-nlm_do_fopen-fails.patch lockd-plug-nlm_file-refcount-leak-on-cached-nlm_do_fopen-failure.patch nvdimm-btt-free-arena-sub-allocations-on-discover_arenas-error-path.patch nvdimm-btt-free-arenas-on-btt_init-error-paths.patch --- diff --git a/queue-5.15/jbd2-fix-integer-underflow-in-jbd2_journal_initialize_fast_commit.patch b/queue-5.15/jbd2-fix-integer-underflow-in-jbd2_journal_initialize_fast_commit.patch new file mode 100644 index 0000000000..5c336951b0 --- /dev/null +++ b/queue-5.15/jbd2-fix-integer-underflow-in-jbd2_journal_initialize_fast_commit.patch @@ -0,0 +1,48 @@ +From 289a2ca0c9b7eae74f93fc213b0b971669b8683d Mon Sep 17 00:00:00 2001 +From: Junrui Luo +Date: Wed, 13 May 2026 17:28:40 +0800 +Subject: jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() + +From: Junrui Luo + +commit 289a2ca0c9b7eae74f93fc213b0b971669b8683d upstream. + +jbd2_journal_initialize_fast_commit() validates journal capacity by +checking (journal->j_last - num_fc_blks < JBD2_MIN_JOURNAL_BLOCKS). +Both j_last and num_fc_blks are unsigned, so when num_fc_blks exceeds +j_last the subtraction wraps to a large value, bypassing the bounds +check. + +The resulting underflow corrupts j_last, j_fc_first, and j_free, +leading to journal abort. + +Fix by checking num_fc_blks against j_last before the subtraction, +returning -EFSCORRUPTED. + +Fixes: 6866d7b3f2bb ("ext4 / jbd2: add fast commit initialization") +Reported-by: Yuhao Jiang +Cc: stable@vger.kernel.org +Signed-off-by: Junrui Luo +Fixes: e029c5f27987 ("ext4: make num of fast commit blocks configurable") +Reviewed-by: Baokun Li +Fixes: e029c5f279872 ("ext4: make num of fast commit blocks configurable") +Reviewed-by: Zhang Yi +Reviewed-by: Jan Kara +Link: https://patch.msgid.link/SYBPR01MB7881663C927DE9D7BBF4D1DFAF062@SYBPR01MB7881.ausprd01.prod.outlook.com +Signed-off-by: Theodore Ts'o +Signed-off-by: Greg Kroah-Hartman +--- + fs/jbd2/journal.c | 2 ++ + 1 file changed, 2 insertions(+) + +--- a/fs/jbd2/journal.c ++++ b/fs/jbd2/journal.c +@@ -2286,6 +2286,8 @@ jbd2_journal_initialize_fast_commit(jour + unsigned long long num_fc_blks; + + num_fc_blks = jbd2_journal_get_num_fc_blks(sb); ++ if (num_fc_blks > journal->j_last) ++ return -EFSCORRUPTED; + if (journal->j_last - num_fc_blks < JBD2_MIN_JOURNAL_BLOCKS) + return -ENOSPC; + diff --git a/queue-5.15/lockd-plug-nlm_file-leak-when-nlm_do_fopen-fails.patch b/queue-5.15/lockd-plug-nlm_file-leak-when-nlm_do_fopen-fails.patch new file mode 100644 index 0000000000..504c63fdc7 --- /dev/null +++ b/queue-5.15/lockd-plug-nlm_file-leak-when-nlm_do_fopen-fails.patch @@ -0,0 +1,38 @@ +From f16a1513452edb532fec81e591c64c320866719c Mon Sep 17 00:00:00 2001 +From: Chuck Lever +Date: Thu, 14 May 2026 16:56:04 -0400 +Subject: lockd: Plug nlm_file leak when nlm_do_fopen() fails + +From: Chuck Lever + +commit f16a1513452edb532fec81e591c64c320866719c upstream. + +A client can repeatedly drive nlm_do_fopen() failures by presenting +file handles that the underlying export rejects. After kzalloc_obj() +succeeds in nlm_lookup_file(), the freshly allocated nlm_file is not +yet inserted into nlm_files[]. The nlm_do_fopen() failure path jumps +to out_unlock, which releases nlm_file_mutex and returns without +freeing the allocation, so each failure leaks one nlm_file. + +Route the failure through out_free so kfree() runs before the +function returns. + +Fixes: 7f024fcd5c97 ("Keep read and write fds with each nlm_file") +Cc: stable@vger.kernel.org +Signed-off-by: Chuck Lever +Signed-off-by: Greg Kroah-Hartman +--- + fs/lockd/svcsubs.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/fs/lockd/svcsubs.c ++++ b/fs/lockd/svcsubs.c +@@ -139,7 +139,7 @@ nlm_lookup_file(struct svc_rqst *rqstp, + + nfserr = nlm_do_fopen(rqstp, file, mode); + if (nfserr) +- goto out_unlock; ++ goto out_free; + + hlist_add_head(&file->f_list, &nlm_files[hash]); + diff --git a/queue-5.15/lockd-plug-nlm_file-refcount-leak-on-cached-nlm_do_fopen-failure.patch b/queue-5.15/lockd-plug-nlm_file-refcount-leak-on-cached-nlm_do_fopen-failure.patch new file mode 100644 index 0000000000..dee8ec1122 --- /dev/null +++ b/queue-5.15/lockd-plug-nlm_file-refcount-leak-on-cached-nlm_do_fopen-failure.patch @@ -0,0 +1,42 @@ +From 70a38f87bed7f0694fd07988b47b2db1e10d8df3 Mon Sep 17 00:00:00 2001 +From: Chuck Lever +Date: Thu, 14 May 2026 16:56:06 -0400 +Subject: lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure + +From: Chuck Lever + +commit 70a38f87bed7f0694fd07988b47b2db1e10d8df3 upstream. + +The cached-file path in nlm_lookup_file() reaches the found: label +unconditionally, even when nlm_do_fopen() fails. At that label +*result and file->f_count are updated before the error is returned. +The wrappers nlm3svc_lookup_file() and nlm4svc_lookup_file() then +bail out of their switch without copying *result back to their +caller, so the proc handler's local nlm_file pointer remains NULL +and the cleanup path skips nlm_release_file(). The f_count +increment is never released, and nlm_traverse_files() can no +longer reap the file because its refcount never returns to zero +between requests. + +Short-circuit the cached path so neither *result nor f_count is +touched when nlm_do_fopen() fails on a hashed nlm_file. + +Fixes: 7f024fcd5c97 ("Keep read and write fds with each nlm_file") +Cc: stable@vger.kernel.org +Signed-off-by: Chuck Lever +Signed-off-by: Greg Kroah-Hartman +--- + fs/lockd/svcsubs.c | 2 ++ + 1 file changed, 2 insertions(+) + +--- a/fs/lockd/svcsubs.c ++++ b/fs/lockd/svcsubs.c +@@ -123,6 +123,8 @@ nlm_lookup_file(struct svc_rqst *rqstp, + mutex_lock(&file->f_mutex); + nfserr = nlm_do_fopen(rqstp, file, mode); + mutex_unlock(&file->f_mutex); ++ if (nfserr) ++ goto out_unlock; + goto found; + } + nlm_debug_print_fh("creating file for", &lock->fh); diff --git a/queue-5.15/nvdimm-btt-free-arena-sub-allocations-on-discover_arenas-error-path.patch b/queue-5.15/nvdimm-btt-free-arena-sub-allocations-on-discover_arenas-error-path.patch new file mode 100644 index 0000000000..135e848e7a --- /dev/null +++ b/queue-5.15/nvdimm-btt-free-arena-sub-allocations-on-discover_arenas-error-path.patch @@ -0,0 +1,41 @@ +From 13fe4cd9ddd0aacb7777812328be525a11ea3fea Mon Sep 17 00:00:00 2001 +From: Abdun Nihaal +Date: Tue, 19 May 2026 11:20:12 +0530 +Subject: nvdimm/btt: Free arena sub-allocations on discover_arenas() error path + +From: Abdun Nihaal + +commit 13fe4cd9ddd0aacb7777812328be525a11ea3fea upstream. + +Memory allocated by btt_freelist_init(), btt_rtt_init(), and +btt_maplocks_init() is not freed on some discover_arenas() error +paths. This leaks memory when arena discovery fails. + +Add the missing kfree() calls to release the allocations before +returning an error. + +[ as: commit message and log edits ] + +Fixes: 5212e11fde4d ("nd_btt: atomic sector updates") +Cc: stable@vger.kernel.org +Signed-off-by: Abdun Nihaal +Reviewed-by: Alison Schofield +Link: https://patch.msgid.link/20260519-nvdimmleaks-v1-1-592300fb7a43@cse.iitm.ac.in +Signed-off-by: Alison Schofield +Signed-off-by: Greg Kroah-Hartman +--- + drivers/nvdimm/btt.c | 3 +++ + 1 file changed, 3 insertions(+) + +--- a/drivers/nvdimm/btt.c ++++ b/drivers/nvdimm/btt.c +@@ -924,6 +924,9 @@ static int discover_arenas(struct btt *b + return ret; + + out: ++ kfree(arena->freelist); ++ kfree(arena->rtt); ++ kfree(arena->map_locks); + kfree(arena); + free_arenas(btt); + out_super: diff --git a/queue-5.15/nvdimm-btt-free-arenas-on-btt_init-error-paths.patch b/queue-5.15/nvdimm-btt-free-arenas-on-btt_init-error-paths.patch new file mode 100644 index 0000000000..79bdaf2ae2 --- /dev/null +++ b/queue-5.15/nvdimm-btt-free-arenas-on-btt_init-error-paths.patch @@ -0,0 +1,72 @@ +From 1a6b6442a982d0ca5fb6a1a39b6f6dfd760eda57 Mon Sep 17 00:00:00 2001 +From: Abdun Nihaal +Date: Tue, 19 May 2026 11:20:13 +0530 +Subject: nvdimm/btt: Free arenas on btt_init() error paths + +From: Abdun Nihaal + +commit 1a6b6442a982d0ca5fb6a1a39b6f6dfd760eda57 upstream. + +The arenas allocated by discover_arenas() or create_arenas() are not +freed on some error paths in btt_init(). This leaks memory when BTT +initialization fails. + +Call free_arenas() from the affected error paths to release the +allocations. + +[ as: commit message and log edits ] + +Fixes: 5212e11fde4d ("nd_btt: atomic sector updates") +Cc: stable@vger.kernel.org +Signed-off-by: Abdun Nihaal +Reviewed-by: Alison Schofield +Link: https://patch.msgid.link/20260519-nvdimmleaks-v1-2-592300fb7a43@cse.iitm.ac.in +Signed-off-by: Alison Schofield +Signed-off-by: Greg Kroah-Hartman +--- + drivers/nvdimm/btt.c | 11 +++++++---- + 1 file changed, 7 insertions(+), 4 deletions(-) + +--- a/drivers/nvdimm/btt.c ++++ b/drivers/nvdimm/btt.c +@@ -1604,7 +1604,7 @@ static struct btt *btt_init(struct nd_bt + if (btt->init_state != INIT_READY && nd_region->ro) { + dev_warn(dev, "%s is read-only, unable to init btt metadata\n", + dev_name(&nd_region->dev)); +- return NULL; ++ goto err; + } else if (btt->init_state != INIT_READY) { + btt->num_arenas = (rawsize / ARENA_MAX_SIZE) + + ((rawsize % ARENA_MAX_SIZE) ? 1 : 0); +@@ -1614,25 +1614,28 @@ static struct btt *btt_init(struct nd_bt + ret = create_arenas(btt); + if (ret) { + dev_info(dev, "init: create_arenas: %d\n", ret); +- return NULL; ++ goto err; + } + + ret = btt_meta_init(btt); + if (ret) { + dev_err(dev, "init: error in meta_init: %d\n", ret); +- return NULL; ++ goto err; + } + } + + ret = btt_blk_init(btt); + if (ret) { + dev_err(dev, "init: error in blk_init: %d\n", ret); +- return NULL; ++ goto err; + } + + btt_debugfs_init(btt); + + return btt; ++err: ++ free_arenas(btt); ++ return NULL; + } + + /** diff --git a/queue-5.15/series b/queue-5.15/series index f215c063bd..9ab6474f76 100644 --- a/queue-5.15/series +++ b/queue-5.15/series @@ -603,3 +603,8 @@ batman-adv-tt-prevent-tvlv-oob-check-overflow.patch mfd-tps6586x-fix-of-node-refcount.patch bluetooth-sco-fix-sleeping-under-spinlock-in-sco_conn_ready.patch bluetooth-sco-hold-sk-properly-in-sco_conn_ready.patch +jbd2-fix-integer-underflow-in-jbd2_journal_initialize_fast_commit.patch +nvdimm-btt-free-arenas-on-btt_init-error-paths.patch +nvdimm-btt-free-arena-sub-allocations-on-discover_arenas-error-path.patch +lockd-plug-nlm_file-leak-when-nlm_do_fopen-fails.patch +lockd-plug-nlm_file-refcount-leak-on-cached-nlm_do_fopen-failure.patch