mainline inclusion from mainline-v7.2-rc1 commit c146284c4355e96550e50e8f6e694223d107b621 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/16904 CVE: CVE-2026-68095 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?i... -------------------------------- Check fch->connected under fch->lock in fuse_uring_create() before attaching a new ring. Without this, a race between fuse_uring_create() and fuse_chan_abort() can result in the ring, queue, and fpq.processing table being created after fuse_uring_abort() has already run, leading to unnecessary allocation and teardown. These are eventually cleaned up by fuse_uring_destruct() but will linger until the process exits, even with the connection aborted. Reviewed-by: Bernd Schubert <bernd@bsbernd.com> Signed-off-by: Joanne Koong <joannelkoong@gmail.com> Signed-off-by: Miklos Szeredi <mszeredi@redhat.com> Signed-off-by: Zhou Minqiang <zhouminqiang2@huawei.com> --- fs/fuse/dev_uring.c | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/fs/fuse/dev_uring.c b/fs/fuse/dev_uring.c index 28aba59188fb..99f5b48dafb5 100644 --- a/fs/fuse/dev_uring.c +++ b/fs/fuse/dev_uring.c @@ -201,6 +201,10 @@ static struct fuse_ring *fuse_uring_create(struct fuse_conn *fc) max_payload_size = max(max_payload_size, fc->max_pages * PAGE_SIZE); spin_lock(&fc->lock); + if (!fc->connected) { + spin_unlock(&fc->lock); + goto out_err; + } if (fc->ring) { /* race, another thread created the ring in the meantime */ spin_unlock(&fc->lock); @@ -944,16 +948,16 @@ static int fuse_uring_do_register(struct fuse_ring_ent *ent, struct fuse_conn *fc = ring->fc; struct fuse_iqueue *fiq = &fc->iq; - spin_lock(&fch->lock); + spin_lock(&fc->lock); /* abort teardown path is running or has run */ - if (!fch->connected) { - spin_unlock(&fch->lock); + if (!fc->connected) { + spin_unlock(&fc->lock); if (atomic_dec_and_test(&ring->queue_refs)) wake_up_all(&ring->stop_waitq); kfree(ent); return -ECONNABORTED; } - spin_unlock(&fch->lock); + spin_unlock(&fc->lock); fuse_uring_prepare_cancel(cmd, issue_flags, ent); -- 2.52.0