From: "syzbot" <syzbot@kernel.org>
To: syzkaller-upstream-moderation@googlegroups.com
Cc: syzbot@lists.linux.dev
Subject: [PATCH RFC] arm64: mm: Attempt exception fixup in do_sea()
Date: Thu, 27 Aug 2026 23:05:09 +0000 (UTC) [thread overview]
Message-ID: <5a2b9a05-0dbb-4e9d-be3f-a6fa2981a6dc@mail.kernel.org> (raw)
When a user-space process maps Device or Non-cacheable memory (such as a
PCI BAR) into its address space and passes that address to a system call
performing atomic user access (such as futex with FUTEX_WAKE_OP), the
kernel executes an exclusive load instruction (ldxr) at EL1. Under the ARM
architecture, exclusive accesses to Device memory are unsupported and can
trigger a Synchronous External Abort (SEA) instead of an Alignment Fault,
routing the exception to do_sea().
Unlike other fault handlers, do_sea() did not check the kernel exception
tables for aborts occurring in kernel mode (!user_mode(regs)). Instead, it
unconditionally treated all kernel-mode SEAs as fatal hardware errors,
marked the kernel tainted with TAINT_MACHINE_CHECK, and called
arm64_notify_die() which panicked the system. As a result, accessing mapped
device memory via such syscalls causes a kernel panic and a local denial of
service.
Fix this by calling fixup_exception() for kernel-mode aborts in do_sea().
If an exception table entry exists for the faulting instruction (such as
uaccess or futex routines), the fault is fixed up and do_sea() returns
gracefully so that the calling system call returns -EFAULT to user space.
If no fixup entry exists, execution continues down the fatal panic path.
Fixes: 32015c235603 ("arm64: exception: handle Synchronous External Abort")
Assisted-by: Gemini:gemini-3.7-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+417a6b7c02d5d03f9aa6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=417a6b7c02d5d03f9aa6
Link: https://syzkaller.appspot.com/ai_job?id=e80ac460-6a7b-4d71-8092-1edf4242c342
To: "Catalin Marinas" <catalin.marinas@arm.com>
To: <linux-arm-kernel@lists.infradead.org>
To: "Will Deacon" <will@kernel.org>
To: "Tyler Baicar" <tbaicar@codeaurora.org>
Cc: "Andrew Morton" <akpm@linux-foundation.org>
Cc: "David Hildenbrand (Arm)" <david@kernel.org>
Cc: <linux-kernel@vger.kernel.org>
Cc: "Quentin Perret" <qperret@google.com>
Cc: "Ryan Roberts" <ryan.roberts@arm.com>
---
diff --git a/arch/arm64/mm/fault.c b/arch/arm64/mm/fault.c
index 0b5255765..ca396b4bd 100644
--- a/arch/arm64/mm/fault.c
+++ b/arch/arm64/mm/fault.c
@@ -878,6 +878,9 @@ static int do_sea(unsigned long far, unsigned long esr, struct pt_regs *regs)
return 0;
}
+ if (!user_mode(regs) && fixup_exception(regs, esr))
+ return 0;
+
if (esr & ESR_ELx_FnV) {
siaddr = 0;
} else {
base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f
--
This is an AI-generated patch subject to moderation.
Reply with '#syz upstream' to Sign-off the patch as a human author
and send it to the upstream kernel mailing lists.
Reply with '#syz reject' to reject it ('#syz unreject' to undo).
See https://goo.gle/syzbot-ai-patches for information about AI-generated patches.
You can comment on the patch as usual, syzbot will try to address
the comments and send a new version of the patch if necessary.
syzbot engineers can be reached at syzkaller@googlegroups.com.
reply other threads:[~2026-08-27 23:05 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5a2b9a05-0dbb-4e9d-be3f-a6fa2981a6dc@mail.kernel.org \
--to=syzbot@kernel.org \
--cc=syzbot@lists.linux.dev \
--cc=syzkaller-upstream-moderation@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox