Re: [PATCH] buffer: fix NULL dereference of bh->b_folio in __bh_submit()

From: Jan Kara

Date: Thu Sep 10 2026 - 07:22:38 EST


On Thu 10-09-26 10:08:55, Konrad Dybcio wrote:
> On 9/2/26 3:33 AM, Joseph Qi wrote:
> > Commit a2c924c240e7 ("buffer: set BIO_COMPLETE_IN_TASK for dropbehind
> > writeback") added an unconditional folio_test_dropbehind(bh->b_folio) in
> > __bh_submit(). But jbd2 shadow buffers have a NULL b_folio since commit
> > 5febcba29792 ("jbd2: point the shadow buffer at the frozen data
> > directly") made them point b_data at the kmalloced frozen data rather
> > than a folio. Submitting such a buffer during journal commit oopses:
> >
> > BUG: kernel NULL pointer dereference, address: 0000000000000000
> > RIP: 0010:__bh_submit.constprop.0+0x87/0x120
> > Call Trace:
> > jbd2_journal_commit_transaction+0x932/0x1b10
> > kjournald2+0xb2/0x250
> >
> > Hit by the ocfs2-testsuite fill_verify_holes test running with
> > data=writeback.
> >
> > Dropbehind only applies to buffers backed by a folio, so skip the check
> > when b_folio is NULL.
> >
> > Fixes: 5febcba29792 ("jbd2: point the shadow buffer at the frozen data directly")
> > Tested-by: Srikanth Aithal <Srikanth.Aithal@xxxxxxx>
> > Tested-by: Luca Weiss <luca.weiss@xxxxxxxxxxxxx> # sm7225-fairphone-fp4
> > Reviewed-by: Jan Kara <jack@xxxxxxx>
> > Signed-off-by: Joseph Qi <joseph.qi@xxxxxxxxxxxxxxxxx>
> > ---
> > fs/buffer.c | 3 ++-
> > 1 file changed, 2 insertions(+), 1 deletion(-)
> >
> > diff --git a/fs/buffer.c b/fs/buffer.c
> > index 427d8a817cd5..f46fa6413032 100644
> > --- a/fs/buffer.c
> > +++ b/fs/buffer.c
> > @@ -1106,7 +1106,8 @@ static void __bh_submit(struct buffer_head *bh, blk_opf_t opf,
> >
> > bio = bio_alloc(bh->b_bdev, 1, opf, GFP_NOIO);
> >
> > - if (folio_test_dropbehind(bh->b_folio) && op_is_write(opf))
> > + if (bh->b_folio && folio_test_dropbehind(bh->b_folio) &&
> > + op_is_write(opf))
> > bio_set_flag(bio, BIO_COMPLETE_IN_TASK);
>
>
> -next has been broken for a week+ already, please pick this up..

Christian has pushed out a branch with the fixed version of the code today
so hopefully it should get fixed in linux-next soon.

Honza
--
Jan Kara <jack@xxxxxxxx>
SUSE Labs, CR