[PATCH 2/2] f2fs: cache: pin cached block in f2fs_unlock_cache()

From: Chao Yu

Date: Wed Sep 30 2026 - 20:13:31 EST


From: Chao Yu <chao@xxxxxxxxxx>

During asynchronous read readahead (e.g., in f2fs_ra_node_cache()), the
caller drops its own reference via f2fs_put_cache(entry, false) immediately
after issuing the read bio, leaving only the radix tree holding an active
reference during I/O flight.

In f2fs_unlock_cache(), clear_and_wake_up_bit() executes two steps:
1. clear_bit_unlock(F2FS_BLOCK_LOCKED, &entry->state): clears the bit.
2. wake_up_bit(&entry->state, F2FS_BLOCK_LOCKED): hashes &entry->state
to find the waitqueue and wake sleeping waiters.

Once step 1 clears the bit, a concurrent waiter in f2fs_lock_cache()
(such as in f2fs_truncate_cache() or f2fs_drop_cache()) is immediately
unblocked. The waiter can acquire the lock, delete the entry from the
radix tree, drop the remaining reference, and kfree() the entry before
step 2 completes. This causes wake_up_bit() to dereference freed memory:

CPU 0 (Read I/O completion) CPU 1 (f2fs_drop_cache / Truncation)
- f2fs_cache_read_end_io()
- f2fs_unlock_cache(entry)
- clear_and_wake_up_bit()
- clear_bit_unlock(LOCKED)
: bit is cleared!
- f2fs_lock_cache(entry)
: acquires lock!
- f2fs_truncate_locked_cache(entry)
- radix_tree_delete(&cache->root, ...)
- entry->cache = NULL;
- atomic_dec(&entry->refcount);
- f2fs_unlock_cache(entry);
- f2fs_put_cache(entry, false);
- atomic_dec_and_test(&refcount) == 0
- f2fs_do_free_cache(entry)
- kfree(entry->data);
- kfree(entry); <--- FREED!
- smp_mb__after_atomic()
- wake_up_bit(&entry->state, ...)
: Dereferences &entry->state on freed entry! (UAF)

Like commit ("f2fs: cache: pin cached block in f2fs_end_cache_writeback()"),
acquire a temporary reference via f2fs_cache_get() before clear_and_wake_up_bit()
and release it with f2fs_cache_put() once wake_up_bit() completes.

This fixes commit 399410a90ca7 ("f2fs: cache: implement metadata cache")

Signed-off-by: Chao Yu <chao@xxxxxxxxxx>
---
fs/f2fs/cache.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)

diff --git a/fs/f2fs/cache.c b/fs/f2fs/cache.c
index 7831e53f5678..04b5408cbc58 100644
--- a/fs/f2fs/cache.c
+++ b/fs/f2fs/cache.c
@@ -18,6 +18,8 @@
#include <trace/events/f2fs.h>
#include "segment.h"

+static bool f2fs_cache_put(struct f2fs_cached_block *entry);
+
void f2fs_cache_wait_writeback_cond(struct f2fs_cached_block *entry,
enum page_type type)
{
@@ -314,7 +316,19 @@ void f2fs_lock_cache(struct f2fs_cached_block *entry)

void f2fs_unlock_cache(struct f2fs_cached_block *entry)
{
+ /*
+ * In asynchronous read I/O completion (e.g. from f2fs_ra_node_cache()),
+ * the I/O completion does not hold a reference of its own. Once
+ * clear_and_wake_up_bit() clears F2FS_BLOCK_LOCKED, a concurrent waiter
+ * in f2fs_lock_cache() (e.g. from f2fs_truncate_cache()) can wake up,
+ * truncate the entry, and drop the final reference before wake_up_bit()
+ * finishes.
+ * Pin the entry here to make sure it is not freed before wake_up_bit()
+ * completes.
+ */
+ f2fs_cache_get(entry);
clear_and_wake_up_bit(F2FS_BLOCK_LOCKED, &entry->state);
+ f2fs_cache_put(entry);
}

bool f2fs_put_cache(struct f2fs_cached_block *entry, bool unlock)
--
2.49.0