Re: [PATCH] buffer: fix NULL dereference of bh->b_folio in __bh_submit()
From: Joseph Qi
Date: Wed Sep 02 2026 - 21:43:22 EST
On 9/3/26 4:52 AM, Yalagada Pavan Kumar wrote:
> On Wed, Sep 02, 2026 at 09:33:57AM +0800, Joseph Qi wrote:
>> Commit a2c924c240e7 ("buffer: set BIO_COMPLETE_IN_TASK for dropbehind
>> writeback") added an unconditional folio_test_dropbehind(bh->b_folio) in
>> __bh_submit(). But jbd2 shadow buffers have a NULL b_folio since commit
>> 5febcba29792 ("jbd2: point the shadow buffer at the frozen data
>> directly") made them point b_data at the kmalloced frozen data rather
>> than a folio. Submitting such a buffer during journal commit oopses:
>>
>> BUG: kernel NULL pointer dereference, address: 0000000000000000
>> RIP: 0010:__bh_submit.constprop.0+0x87/0x120
>> Call Trace:
>> jbd2_journal_commit_transaction+0x932/0x1b10
>> kjournald2+0xb2/0x250
>>
>> Hit by the ocfs2-testsuite fill_verify_holes test running with
>> data=writeback.
>>
>> Dropbehind only applies to buffers backed by a folio, so skip the check
>> when b_folio is NULL.
>>
> Hi,
>
> I was working on a fix for this syzbot report [1] and didn't realize that you were
> already working on it. I noticed your patch on the mailing list, so i won't
> send a duplicate patch.
>
>> Fixes: 5febcba29792 ("jbd2: point the shadow buffer at the frozen data directly")
>
> Could you please add the Reported-by: and Closes: tags from the syzbot report
> to your patch? This will help syzbot associate the patch with the reported
> issue and track the fix.
>
> [1]: https://syzkaller.appspot.com/bug?extid=41453ea05ab61c075f1f
>
Hi Christian,
Could you please address the above when apply the patch? Or should I
resend the patch with them?
Thanks,
Joseph