From: Lance Yang <lance.yang@linux.dev>
To: akpm@linux-foundation.org
Cc: neganhat@gmail.com, david@kernel.org, jgg@ziepe.ca,
jhubbard@nvidia.com, peterx@redhat.com, linux-mm@kvack.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] mm/gup: fix NULL pointer dereference in fixup_user_fault()
Date: Mon, 5 Oct 2026 10:19:57 +0800 [thread overview]
Message-ID: <20261005021957.5254-1-lance.yang@linux.dev> (raw)
In-Reply-To: <20261004125601.c06953a6f0660df9859b0c2a@linux-foundation.org>
On Sun, Oct 04, 2026 at 12:56:01PM -0700, Andrew Morton wrote:
>On Sun, 4 Oct 2026 02:48:46 +0700 Nguyen Duy Nhat Anh <neganhat@gmail.com> wrote:
>
>> In fixup_user_fault(), the 'unlocked' parameter is checked for NULL
>> early on, allowing callers to pass NULL if they do not track whether the
>> mmap lock was dropped.
>>
>> However, if handle_mm_fault() returns VM_FAULT_COMPLETED, line 1597
>> dereferences 'unlocked' directly (*unlocked = true) without checking
>> if it is NULL. Callers like s390's pci_mmio.c pass NULL for 'unlocked',
>> leading to a kernel NULL pointer dereference when VM_FAULT_COMPLETED
>> occurs.
>>
>> Fix this by checking if 'unlocked' is non-NULL before assigning to it.
>
>This code is too subtle so you aren't the first to attempt to "fix" it.
>
>The key hint is in the kerneldoc:
>
> * @unlocked: did we unlock the mmap_lock while retrying, maybe NULL if caller
> * does not allow retry. If NULL, the caller must guarantee
> * that fault_flags does not contain FAULT_FLAG_ALLOW_RETRY.
>
>Trace through the
>FAULT_FLAG_ALLOW_RETRY/VM_FAULT_COMPLETED/VM_FAULT_RETRY logic
>to confirm that the null deref is a cant-happen.
IIUC, that's indeed a can't-happen :)
next prev parent reply other threads:[~2026-10-05 2:20 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 19:48 [PATCH] mm/gup: fix NULL pointer dereference in fixup_user_fault() Nguyen Duy Nhat Anh
2026-10-04 19:56 ` Andrew Morton
2026-10-05 2:19 ` Lance Yang [this message]
2026-10-05 10:27 ` David Hildenbrand (Arm)
2026-10-05 9:37 ` [PATCH v2] mm/gup: document unlocked invariant in fixup_user_fault Nguyen Duy Nhat Anh
2026-10-05 10:29 ` David Hildenbrand (Arm)
2026-10-05 11:22 ` Nhật Anh Nguyễn Duy
2026-10-07 10:58 ` David Hildenbrand (Arm)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005021957.5254-1-lance.yang@linux.dev \
--to=lance.yang@linux.dev \
--cc=akpm@linux-foundation.org \
--cc=david@kernel.org \
--cc=jgg@ziepe.ca \
--cc=jhubbard@nvidia.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=neganhat@gmail.com \
--cc=peterx@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.