All of lore.kernel.org
 help / color / mirror / Atom feed
From: Suren Baghdasaryan <surenb@google.com>
To: akpm@linux-foundation.org
Cc: hughd@google.com, hannes@cmpxchg.org, david@redhat.com,
	vincent.whitchurch@axis.com, seanjc@google.com, rppt@kernel.org,
	shy828301@gmail.com, pasha.tatashin@soleen.com,
	paul.gortmaker@windriver.com, peterx@redhat.com, vbabka@suse.cz,
	Liam.Howlett@Oracle.com, ccross@google.com, willy@infradead.org,
	arnd@arndb.de, cgel.zte@gmail.com, yuzhao@google.com,
	bagasdotme@gmail.com, suleiman@google.com, steven@liquorix.net,
	heftig@archlinux.org, cuigaosheng1@huawei.com,
	kirill@shutemov.name, linux-kernel@vger.kernel.org,
	linux-fsdevel@vger.kernel.org, linux-mm@kvack.org,
	surenb@google.com,
	syzbot+91edf9178386a07d06a7@syzkaller.appspotmail.com
Subject: [PATCH v2 1/1] mm: fix vma->anon_name memory leak for anonymous shmem VMAs
Date: Wed,  4 Jan 2023 16:02:40 -0800	[thread overview]
Message-ID: <20230105000241.1450843-1-surenb@google.com> (raw)

free_anon_vma_name() is missing a check for anonymous shmem VMA which
leads to a memory leak due to refcount not being dropped.  Fix this by
calling anon_vma_name_put() unconditionally. It will free vma->anon_name
whenever it's non-NULL.

Fixes: d09e8ca6cb93 ("mm: anonymous shared memory naming")
Signed-off-by: Suren Baghdasaryan <surenb@google.com>
Suggested-by: David Hildenbrand <david@redhat.com>
Reported-by: syzbot+91edf9178386a07d06a7@syzkaller.appspotmail.com
Cc: David Hildenbrand <david@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Pasha Tatashin <pasha.tatashin@soleen.com>
---
applies over mm-hotfixes-unstable branch of
git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm tree after reverting
the original version of this patch.

 include/linux/mm_inline.h | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/include/linux/mm_inline.h b/include/linux/mm_inline.h
index e8ed225d8f7c..ff3f3f23f649 100644
--- a/include/linux/mm_inline.h
+++ b/include/linux/mm_inline.h
@@ -413,8 +413,7 @@ static inline void free_anon_vma_name(struct vm_area_struct *vma)
 	 * Not using anon_vma_name because it generates a warning if mmap_lock
 	 * is not held, which might be the case here.
 	 */
-	if (!vma->vm_file)
-		anon_vma_name_put(vma->anon_name);
+	anon_vma_name_put(vma->anon_name);
 }
 
 static inline bool anon_vma_name_eq(struct anon_vma_name *anon_name1,
-- 
2.39.0.314.g84b9a713c41-goog


             reply	other threads:[~2023-01-05  0:03 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-01-05  0:02 Suren Baghdasaryan [this message]
2023-01-05  1:38 ` [PATCH v2 1/1] mm: fix vma->anon_name memory leak for anonymous shmem VMAs Andrew Morton
2023-01-05  2:39   ` Suren Baghdasaryan
2023-01-05  9:03     ` David Hildenbrand
2023-01-05 12:07       ` Holger Hoffstätte
2023-01-05 12:18         ` David Hildenbrand
2023-01-05  9:04 ` David Hildenbrand

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230105000241.1450843-1-surenb@google.com \
    --to=surenb@google.com \
    --cc=Liam.Howlett@Oracle.com \
    --cc=akpm@linux-foundation.org \
    --cc=arnd@arndb.de \
    --cc=bagasdotme@gmail.com \
    --cc=ccross@google.com \
    --cc=cgel.zte@gmail.com \
    --cc=cuigaosheng1@huawei.com \
    --cc=david@redhat.com \
    --cc=hannes@cmpxchg.org \
    --cc=heftig@archlinux.org \
    --cc=hughd@google.com \
    --cc=kirill@shutemov.name \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=pasha.tatashin@soleen.com \
    --cc=paul.gortmaker@windriver.com \
    --cc=peterx@redhat.com \
    --cc=rppt@kernel.org \
    --cc=seanjc@google.com \
    --cc=shy828301@gmail.com \
    --cc=steven@liquorix.net \
    --cc=suleiman@google.com \
    --cc=syzbot+91edf9178386a07d06a7@syzkaller.appspotmail.com \
    --cc=vbabka@suse.cz \
    --cc=vincent.whitchurch@axis.com \
    --cc=willy@infradead.org \
    --cc=yuzhao@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.