All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Liu Dalin" <liudalin@kylinsec.com.cn>
Cc: "Heiko Carstens" <hca@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	linux-s390@vger.kernel.org,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH] arch/s390/pci: fix fixup_user_fault() calls with NULL unlocked parameter
Date: Wed, 26 Aug 2026 06:51:34 +0000	[thread overview]
Message-ID: <20260826065134.E9B661F000E9@smtp.kernel.org> (raw)
In-Reply-To: <0726CF177011E0E2+20260826064228.3255764-1-liudalin@kylinsec.com.cn>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Changing the 'unlocked' parameter of fixup_user_fault() from NULL to &unlocked allows the mmap_lock to be temporarily dropped, causing a Use-After-Free of the VMA pointer.
--

commit 440b0dda47238ff5981413f278a2a1abe962cdd0
Author: Liu Dalin <liudalin@kylinsec.com.cn>
arch/s390/pci: fix fixup_user_fault() calls with NULL unlocked parameter

This patch provides a valid unlocked variable to fixup_user_fault() in
the s390 PCI MMIO read and write handlers to properly track the lock state,
resolving an issue where the lock state was obfuscated by passing NULL.

> diff --git a/arch/s390/pci/pci_mmio.c b/arch/s390/pci/pci_mmio.c
> index f3f79ba78410a..5ef2d6436d4b1 100644
> --- a/arch/s390/pci/pci_mmio.c
> +++ b/arch/s390/pci/pci_mmio.c
> @@ -182,7 +182,9 @@ SYSCALL_DEFINE3(s390_pci_mmio_write, unsigned long, mmio_addr,
>  	args.vma = vma;
>  	ret = follow_pfnmap_start(&args);
>  	if (ret) {
> -		fixup_user_fault(current->mm, mmio_addr, FAULT_FLAG_WRITE, NULL);
> +		bool unlocked = false;
> +
> +		fixup_user_fault(current->mm, mmio_addr, FAULT_FLAG_WRITE, &unlocked);
>  		ret = follow_pfnmap_start(&args);

[Severity: Critical]
If fixup_user_fault() drops the mmap_read_lock and sets unlocked to true,
a concurrent munmap() could free the VMA. Since args.vma was populated
earlier, calling follow_pfnmap_start(&args) immediately after would 
dereference the freed VMA pointer:

mm/memory.c:follow_pfnmap_start() {
	struct vm_area_struct *vma = args->vma;
	...
	struct mm_struct *mm = vma->vm_mm;

Can this regression be avoided by checking the unlocked state and handling
the possibility that the VMA is no longer valid?

>  		if (ret)
>  			goto out_unlock_mmap;

[ ... ]

> @@ -335,7 +337,9 @@ SYSCALL_DEFINE3(s390_pci_mmio_read, unsigned long, mmio_addr,
>  	args.address = mmio_addr;
>  	ret = follow_pfnmap_start(&args);
>  	if (ret) {
> -		fixup_user_fault(current->mm, mmio_addr, 0, NULL);
> +		bool unlocked = false;
> +
> +		fixup_user_fault(current->mm, mmio_addr, 0, &unlocked);
>  		ret = follow_pfnmap_start(&args);

[Severity: Critical]
Similarly in s390_pci_mmio_read(), if the lock is temporarily dropped by
fixup_user_fault(), can this second call to follow_pfnmap_start() cause a
use-after-free regression by accessing the stale args.vma pointer?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/0726CF177011E0E2+20260826064228.3255764-1-liudalin@kylinsec.com.cn?part=1

  reply	other threads:[~2026-08-26  6:51 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26  6:42 [PATCH] arch/s390/pci: fix fixup_user_fault() calls with NULL unlocked parameter Liu Dalin
2026-08-26  6:51 ` sashiko-bot [this message]
2026-09-07 15:25 ` Gerd Bayer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260826065134.E9B661F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=liudalin@kylinsec.com.cn \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.