Files
Centos-kernel-stream-9/io_uring
Jeff Moyer 57ff2f3218 io_uring/kbuf: check if target buffer list is still legacy on recycle
This is a backport from Ming.  Here is Ming's changelog:

JIRA: https://redhat.atlassian.net/browse/RHEL-161185
Conflicts: io_uring/kbuf.c
  - Upstream uses kfree(buf) to free the orphaned buffer; downstream
    allocates io_buffer from the io_buf_cachep slab cache, so
    kmem_cache_free(io_buf_cachep, buf) is used instead.
  - Upstream removed the req->buf_index assignment entirely; downstream
    still needs it for the next buffer selection, so it is kept but moved
    before the conditional to avoid use-after-free on buf->bgid.
  - Upstream has bl->nbufs++ tracking which does not exist downstream;
    dropped from the backport.

commit c2c185be5c85d37215397c8e8781abf0a69bec1f
Author: Jens Axboe <axboe@kernel.dk>
Date:   Thu Mar 12 08:59:25 2026 -0600

    io_uring/kbuf: check if target buffer list is still legacy on recycle

    There's a gap between when the buffer was grabbed and when it
    potentially gets recycled, where if the list is empty, someone
    could've upgraded it to a ring provided type. The legacy recycling
    doesn't check if the buffer_list still exists and is of the right
    type. Add those checks.

    Cc: stable@vger.kernel.org
    Reported-by: Keenan Dong <keenanat2000@gmail.com>
    Fixes: c7fb19428d67 ("io_uring: add support for ring mapped supplied buffers")
    Signed-off-by: Jens Axboe <axboe@kernel.dk>

Signed-off-by: Ming Lei <ming.lei@redhat.com>
Signed-off-by: Jeff Moyer <jmoyer@redhat.com>
2026-04-30 20:07:57 -04:00
..
2025-10-27 13:08:30 -04:00
2025-10-27 13:08:30 -04:00
2026-03-09 11:55:21 -04:00
2025-10-27 13:08:30 -04:00
2024-11-28 15:35:44 -05:00