From: Muchun Song <muchun.song@linux.dev>
To: Sourav Panda <souravpanda@google.com>
Cc: osalvador@suse.de, akpm@linux-foundation.org,
usama.arif@linux.dev, shakeel.butt@linux.dev,
wangkefeng.wang@huawei.com, anshuman.khandual@arm.com,
david@kernel.org, surenb@google.com, fvdl@google.com,
gthelen@google.com, hannes@cmpxchg.org, riel@surriel.com,
sj@kernel.org, vbabka@suse.cz, mhocko@suse.com,
bjackman@google.com, zi.yan@sent.com, linux-mm@kvack.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v7] mm/hugetlb_cma: Fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio
Date: Tue, 11 Aug 2026 15:07:56 +0800 [thread overview]
Message-ID: <B16D9053-4BE0-4C7E-9D41-6BDD2096CB75@linux.dev> (raw)
In-Reply-To: <20260811052909.475635-1-souravpanda@google.com>
> On Aug 11, 2026, at 13:29, Sourav Panda <souravpanda@google.com> wrote:
>
> alloc_buddy_hugetlb_folio_with_mpol() can pass a NULL nodemask to
> alloc_fresh_hugetlb_folio() as a fallback to allocate from all
> nodes. If order is gigantic, alloc_fresh_hugetlb_folio() propagates
> the NULL nodemask down to hugetlb_cma_alloc_frozen_folio() via
> alloc_gigantic_frozen_folio().
>
> Additionally, hugetlb_cma_alloc_frozen_folio() previously attempted
> allocation on hugetlb_cma[nid] without verifying if nid is included in
> the caller's nodemask. Adding a node_isset(nid, *nodemask) check ensures
> the initial preferred node allocation honors the memory policy / nodemask.
>
> However, hugetlb_cma_alloc_frozen_folio() dereferences the nodemask in
> node_isset(nid, *nodemask) and for_each_node_mask(node, *nodemask),
> leading to a null pointer dereference kernel panic when nodemask is NULL.
>
> Fix this by checking if nodemask is NULL in
> hugetlb_cma_alloc_frozen_folio() and defaulting it to
> cpuset_current_mems_allowed. Enclose the allocation attempts within
> the cpuset seqcount retry loop so that if the cpuset changes concurrently
> during allocation, the attempts are retried using the updated nodemask.
> This ensures that the initial node check and fallback loop safely honor
> the task's cpuset without violating cpuset constraints or causing NULL
> pointer dereferences or unexpected allocation failures.
>
> From a userspace perspective, this bug allows an unprivileged user to
> crash the kernel (trigger a panic) by requesting a gigantic hugepage
> allocation with MPOL_PREFERRED_MANY on a system where CMA is only
> configured on a subset of NUMA nodes.
>
> This can be reproduced by booting a VM with two NUMA nodes, restricting
> CMA to Node 1 (e.g., hugetlb_cma=1:1G default_hugepagesz=1G
> hugepagesz=1G hugepages=0), and running a program that allocates a
> 1GB hugepage area without reserving, restricts allocation to Node 0
> using mbind() with MPOL_PREFERRED_MANY, and triggers a page fault:
>
> void *ptr = mmap(NULL, 1UL << 30, PROT_READ | PROT_WRITE,
> MAP_PRIVATE | MAP_ANONYMOUS | MAP_HUGETLB |
> MAP_HUGE_1GB | MAP_NORESERVE, -1, 0);
> unsigned long nodemask = 1; /* Node 0 */
> mbind(ptr, 1UL << 30, MPOL_PREFERRED_MANY, &nodemask,
> sizeof(nodemask) * 8, 0);
> memset(ptr, 0, 1UL << 30); /* Trigger fault */
>
> This results in a NULL pointer dereference:
>
> BUG: kernel NULL pointer dereference, address: 0000000000000000
> #PF: supervisor read access in kernel mode
> #PF: error_code(0x0000) - not-present page
> Oops: Oops: 0000 [#1] SMP NOPTI
> RIP: 0010:hugetlb_cma_alloc_frozen_folio+0x75/0x120
> Call Trace:
> <TASK>
> only_alloc_fresh_hugetlb_folio.isra.0+0x2c/0x160
> alloc_surplus_hugetlb_folio+0x6d/0x100
> alloc_hugetlb_folio+0x3c5/0x660
> hugetlb_no_page+0x3d9/0x650
>
> Fixes: eb02f14c4a2b ("mm/hugetlb: allow overcommitting gigantic hugepages")
> Cc: stable@vger.kernel.org
> Signed-off-by: Sourav Panda <souravpanda@google.com>
Reviewed-by: Muchun Song <muchun.song@linux.dev>
Thanks.
next prev parent reply other threads:[~2026-08-11 7:08 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 5:29 [PATCH v7] mm/hugetlb_cma: Fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio Sourav Panda
2026-08-11 7:07 ` Muchun Song [this message]
2026-08-11 8:14 ` Anshuman Khandual
2026-08-12 1:55 ` Andrew Morton
2026-08-12 2:02 ` Muchun Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=B16D9053-4BE0-4C7E-9D41-6BDD2096CB75@linux.dev \
--to=muchun.song@linux.dev \
--cc=akpm@linux-foundation.org \
--cc=anshuman.khandual@arm.com \
--cc=bjackman@google.com \
--cc=david@kernel.org \
--cc=fvdl@google.com \
--cc=gthelen@google.com \
--cc=hannes@cmpxchg.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mhocko@suse.com \
--cc=osalvador@suse.de \
--cc=riel@surriel.com \
--cc=shakeel.butt@linux.dev \
--cc=sj@kernel.org \
--cc=souravpanda@google.com \
--cc=surenb@google.com \
--cc=usama.arif@linux.dev \
--cc=vbabka@suse.cz \
--cc=wangkefeng.wang@huawei.com \
--cc=zi.yan@sent.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.