)]}'
{
  "commit": "ab5449e6af743561ec3d078ea8fcec22a07d8e75",
  "tree": "137fb80b735bfcddea6f0c495beea76a5be7e622",
  "parents": [
    "ce90a179d9a0ddde89a890bc65aed525803b992c"
  ],
  "author": {
    "name": "Angel Adetula",
    "email": "angeladetula@google.com",
    "time": "Thu Apr 30 19:47:37 2026 +0000"
  },
  "committer": {
    "name": "Angel Adetula",
    "email": "angeladetula@google.com",
    "time": "Fri May 01 14:19:56 2026 -0700"
  },
  "message": "bcache: fix cached_dev.sb_bio use-after-free and crash\n\ncommit fec114a98b8735ee89c75216c45a78e28be0f128 upstream.\n\nIn our production environment, we have received multiple crash reports\nregarding libceph, which have caught our attention:\n\n```\n[6888366.280350] Call Trace:\n[6888366.280452]  blk_update_request+0x14e/0x370\n[6888366.280561]  blk_mq_end_request+0x1a/0x130\n[6888366.280671]  rbd_img_handle_request+0x1a0/0x1b0 [rbd]\n[6888366.280792]  rbd_obj_handle_request+0x32/0x40 [rbd]\n[6888366.280903]  __complete_request+0x22/0x70 [libceph]\n[6888366.281032]  osd_dispatch+0x15e/0xb40 [libceph]\n[6888366.281164]  ? inet_recvmsg+0x5b/0xd0\n[6888366.281272]  ? ceph_tcp_recvmsg+0x6f/0xa0 [libceph]\n[6888366.281405]  ceph_con_process_message+0x79/0x140 [libceph]\n[6888366.281534]  ceph_con_v1_try_read+0x5d7/0xf30 [libceph]\n[6888366.281661]  ceph_con_workfn+0x329/0x680 [libceph]\n```\n\nAfter analyzing the coredump file, we found that the address of\ndc-\u003esb_bio has been freed. We know that cached_dev is only freed when it\nis stopped.\n\nSince sb_bio is a part of struct cached_dev, rather than an alloc every\ntime.  If the device is stopped while writing to the superblock, the\nreleased address will be accessed at endio.\n\nThis patch hopes to wait for sb_write to complete in cached_dev_free.\n\nIt should be noted that we analyzed the cause of the problem, then tell\nall details to the QWEN and adopted the modifications it made.\n\nBUG\u003db/506404196\nTEST\u003dpresubmit\nRELEASE_NOTE\u003dFixed CVE-2026-31580 in the Linux kernel.\n\nChange-Id: I65d7c2ad1aff23d5845ef2df8e0d3ba240a812c8\nSigned-off-by: Mingzhe Zou \u003cmingzhe.zou@easystack.cn\u003e\nFixes: cafe563591446 (\"bcache: A block layer cache\")\nCc: stable@vger.kernel.org # 3.10+\nSigned-off-by: Coly Li \u003ccolyli@fnnas.com\u003e\nLink: https://patch.msgid.link/20260322134102.480107-1-colyli@fnnas.com\nSigned-off-by: Jens Axboe \u003caxboe@kernel.dk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Angel Adetula \u003cangeladetula@google.com\u003e\nReviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/148007\nTested-by: Cusky Presubmit Bot \u003cpresubmit@cos-infra-prod.iam.gserviceaccount.com\u003e\nReviewed-by: Robert Kolchmeyer \u003crkolchmeyer@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "017a1ef42f1b086bfe9a48e923469d98c33d9c97",
      "old_mode": 33188,
      "old_path": "drivers/md/bcache/super.c",
      "new_id": "6e0ac0958c10b59968e60446a79c8f8212e865df",
      "new_mode": 33188,
      "new_path": "drivers/md/bcache/super.c"
    }
  ]
}
