All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v5 0/3] mm: khugepaged: fix tracepoint UAF
@ 2026-09-09  2:58 Vernon Yang
  2026-09-09  2:58 ` [PATCH v5 1/3] mm: khugepaged: fix swap entry value to folio_pfn() Vernon Yang
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Vernon Yang @ 2026-09-09  2:58 UTC (permalink / raw)
  To: akpm, david, ljs
  Cc: nico.pache, ryan.roberts, dev.jain, baohua, lance.yang,
	usama.arif, zokeefe, linux-kernel, linux-mm, stable, Vernon Yang

From: Vernon Yang <yanglincheng@kylinos.cn>

The khugepaged tracepoints take a folio pointer and call folio_pfn(),
but by then the folio may no longer be valid: freed after folio_put(),
folio_unlock() or pte_unmap_unlock(), or not a folio at all but an
xarray-encoded swap entry. On classic SPARSEMEM, dereferencing it oopses
khugepaged as soon as the trace event is enabled; on other memory models
it merely prints a bogus pfn.

Pass the pfn to the tracepoints directly, captured while the folio is
still pinned, closing the use-after-free windows in
mm_khugepaged_scan_file(), mm_khugepaged_scan_pmd() and
mm_khugepaged_collapse_file().

This series is based on mm-new + revert v4.

V4 -> V5:
- Use a single trace statement.
- Collect Acked-by.

V3 -> V4:
- Only trace the PFN if it really was problematic.
- Calling the respective trace_xxx() functions separately on success and
  failure.
- Set new_pfn once after successful alloc_charge_folio().

V2 -> V3:
- Place folio_pfn() inside the xas_for_each() loop in PATCH#1.
- Already defaulted the pfn value to -1, to simple it in PATCH#2.

V1 -> V2:
- Instead of passing the folio, just pass the pfn directly.
- Using the folio_pfn() before dropping the reference or the page table
  lock.

V4 : https://lore.kernel.org/linux-mm/20260828055926.346744-1-vernon2gm@gmail.com/
V3 : https://lore.kernel.org/linux-mm/20260824092935.73892-1-vernon2gm@gmail.com/
V2 : https://lore.kernel.org/linux-mm/20260815051924.194810-1-vernon2gm@gmail.com/
V1 : https://lore.kernel.org/linux-mm/20260811133655.267739-1-vernon2gm@gmail.com/

Vernon Yang (3):
  mm: khugepaged: fix swap entry value to folio_pfn()
  mm: khugepaged: fix folio is used after pte_unmap_unlock()
  mm: khugepaged: fix folio is used after folio_put/unlock()

 include/trace/events/huge_memory.h | 18 +++++++++---------
 mm/khugepaged.c                    | 21 ++++++++++++++++++---
 2 files changed, 27 insertions(+), 12 deletions(-)

--
2.53.0



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-09  6:58 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09  2:58 [PATCH v5 0/3] mm: khugepaged: fix tracepoint UAF Vernon Yang
2026-09-09  2:58 ` [PATCH v5 1/3] mm: khugepaged: fix swap entry value to folio_pfn() Vernon Yang
2026-09-09  2:58 ` [PATCH v5 2/3] mm: khugepaged: fix folio is used after pte_unmap_unlock() Vernon Yang
2026-09-09  2:58 ` [PATCH v5 3/3] mm: khugepaged: fix folio is used after folio_put/unlock() Vernon Yang
2026-09-09  6:58 ` [PATCH v5 0/3] mm: khugepaged: fix tracepoint UAF Andrew Morton

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.