Re: [PATCH] sysfs: prevent writing excessively large files

From: David Laight

Date: Thu Sep 17 2026 - 06:08:48 EST


On Thu, 17 Sep 2026 08:34:46 +0100
Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx> wrote:

> On Tue, Sep 15, 2026 at 08:20:17PM +0800, Edward Adam Davis wrote:
> > Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
> > file write via sysfs_kf_write() may result in an out-of-bounds read when
> > checking for the null terminator of a string element in the kobject_actions
> > array within kobject_action_type(), potentially hitting:
> >
> > BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
> > BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
> > Call Trace:
> > kobject_action_type lib/kobject_uevent.c:86 [inline]
> > kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
> > bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
> > bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
> > sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
> > kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
> > new_sync_write fs/read_write.c:595 [inline]
> > vfs_write+0x6af/0x1050 fs/read_write.c:687
> >
> > Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
> > properly.
> >
> > Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
> > Reported-by: syzbot+9a321aea9d851b299486@xxxxxxxxxxxxxxxxxxxxxxxxx
> > Closes: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
> > Tested-by: syzbot+9a321aea9d851b299486@xxxxxxxxxxxxxxxxxxxxxxxxx
> > Signed-off-by: Edward Adam Davis <eadavis@xxxxxxxx>
> > ---
> > fs/sysfs/file.c | 2 ++
> > 1 file changed, 2 insertions(+)
> >
> > diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
> > index cd5bb0f9fee6..a63130d18680 100644
> > --- a/fs/sysfs/file.c
> > +++ b/fs/sysfs/file.c
> > @@ -228,10 +228,12 @@ static const struct kernfs_ops sysfs_file_kfops_ro = {
> > };
> >
> > static const struct kernfs_ops sysfs_file_kfops_wo = {
> > + .atomic_write_len = PAGE_SIZE,
> > .write = sysfs_kf_write,
> > };
> >
> > static const struct kernfs_ops sysfs_file_kfops_rw = {
> > + .atomic_write_len = PAGE_SIZE,
> > .seq_show = sysfs_kf_seq_show,
> > .write = sysfs_kf_write,
> > };
> > --
> > 2.43.0
> >
>
> Are you sure this will not break those sysfs files that want larger page
> sizes? Given the age of this "issue" it's really worrying to me to
> change it now...

If you allowed to leave atomic_write_len as zero then the code shouldn't
let an overlong write through (or should truncate it).
So there must be a bug somewhere else.

Do we know the length for the test that failed?

'atomic_write_len' is also badly named - probably historical.
There is no code to loop over the fragments of a long write and (IIRC) the
write offset is always zero.

There is also some (horrid) related code that can reserve a page buffer
(per node) just in case an access is made when kernel memory isn't
available.
(a flag and a single global page would suffice...)

David


>
> thanks,
>
> greg k-h
>