Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
dm cache policy smq: fix missing locks in invalidating cache blocks
In passthrough mode, the policy invalidate_mapping operation is called simultaneously from multiple workers, thus it should be protected by a lock. Otherwise, we might end up with data races on the allocated blocks counter, or even use-after-free issues with internal data structures when doing concurrent writes.
Note that the existing FIXME in smq_invalidate_mapping() doesn’t affect passthrough mode since migration tasks don’t exist there, but would need attention if supporting fast device shrinking via suspend/resume without target reloading.
Reproduce steps:
- Create a cache device consisting of 1024 cache entries
dmsetup create cmeta –table “0 8192 linear /dev/sdc 0”
dmsetup create cdata –table “0 131072 linear /dev/sdc 8192”
dmsetup create corig –table “0 262144 linear /dev/sdc 262144”
dd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct
dmsetup create cache –table “0 262144 cache /dev/mapper/cmeta
/dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0”
- Populate the cache, and record the number of cached blocks
fio –name=populate –filename=/dev/mapper/cache –rw=randwrite –bs=4k
–size=64m –direct=1
nr_cached=$(dmsetup status cache | awk ‘{split($7, a, “/”); print a[1]}’)
- Reload the cache into passthrough mode
dmsetup suspend cache
dmsetup reload cache –table “0 262144 cache /dev/mapper/cmeta
/dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 passthrough smq 0”
dmsetup resume cache
- Write to the passthrough cache. By setting multiple jobs with I/O size equal to the cache block size, cache blocks are invalidated concurrently from different workers.
fio –filename=/dev/mapper/cache –name=test –rw=randwrite –bs=64k
–direct=1 –numjobs=2 –randrepeat=0 –size=64m
- Check if demoted matches cached block count. These numbers should match but may differ due to the data race.
nr_demoted=$(dmsetup status cache | awk ‘{print $12}’) echo “$nr_cached, $nr_demoted”
Details
- Affected product:
- AlmaLinux 9.2 ESU , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , TuxCare 9.6 ESU , Ubuntu 20.04 ELS
- Affected packages:
- kernel @ 5.14.0 (+7 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Amazon Linux 2023 | Planned | — |
| Debian 11 | Planned | — |
| Debian 11 cloud | Planned | — |
| Debian 12 | Planned | — |
| Debian 13 | In Rollout |
10 kernels
|
| Ubuntu 22.04 | Planned | — |
| Ubuntu 24.04 | Planned | — |