During raid1 reshape operations, a use-after-free can occur in the mempool wait queue when r1bio_pool->curr_nr drops below min_nr. This happens because: 1. mempool_init() initializes wait queue head on stack 2. The stack-allocated wait queue is copied to conf->r1bio_pool through structure assignment 3. wake_up() on this invalid wait queue causes panic when accessing the stack memory that no longer exists Fix this by properly reinitializing the mempool's wait queue using init_waitqueue_head(), ensuring the wait queue structure remains valid throughout the reshape operation. Signed-off-by: Wang Jinchao <wangjinchao600@xxxxxxxxx> --- drivers/md/raid1.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/md/raid1.c b/drivers/md/raid1.c index 19c5a0ce5a40..fd4ce2a4136f 100644 --- a/drivers/md/raid1.c +++ b/drivers/md/raid1.c @@ -3428,6 +3428,7 @@ static int raid1_reshape(struct mddev *mddev) /* ok, everything is stopped */ oldpool = conf->r1bio_pool; conf->r1bio_pool = newpool; + init_waitqueue_head(&conf->r1bio_pool.wait); for (d = d2 = 0; d < conf->raid_disks; d++) { struct md_rdev *rdev = conf->mirrors[d].rdev; -- 2.43.0