Received: by 2002:a05:6a10:7420:0:0:0:0 with SMTP id hk32csp232259pxb; Tue, 15 Feb 2022 12:03:34 -0800 (PST) X-Google-Smtp-Source: ABdhPJwjbOheD5BAgQFMRsvXNBkd5ZSXzZbn+ZUNStmVUyhnFofqkGBGrd3dNAqtPkHfXo8VgAgN X-Received: by 2002:a17:906:7308:: with SMTP id di8mr562234ejc.769.1644955413751; Tue, 15 Feb 2022 12:03:33 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1644955413; cv=none; d=google.com; s=arc-20160816; b=wA+uRYSEMklxu57LCj9lhuI+QWWRAvMXHdYo2NXGF6X2xz7SsprvQW51frjmA9aHt8 kMqT01xavKKwnkVL+zfF92N6h/E6E7rwEhpZF6HK8mYV2HbAje7Gu3oxYp6Hi/9LHlYn eceCgqmWpnApAj/KNTplnMrm0oF1bLyZ1X5VPejfT94bA+6MmAjqhbDU9hpdqRCIOdlj OU6JK2KwIWf+3FkkTe/mQ/YWOOraZigO/rNZya5hf+X03ZYj+RUbdHy+/R8tHX31Qrd+ EJdQExCn/0XmyjNB5p6u6KCuZxQc8sWUk+mC0CjzWfIdWH6MvfuWR7/QBtU13YwaAyh9 g/9g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=fcf+8o+t6+WnOwFW3ZI0zrWbIEyxTwbnoswnCVbg8F8=; b=pU38ODkaen0Te1wEmD4HleClvHxbLOB1t064Mc72ryQ8DeStLtV/i1h0uynif1B+GP XfKbCTInePBTvkg4zo0SqljgMybk2jIBFu6fUa7yyP1zwoMzRLV4ZpNC5jC+UF9XNzHi YzdDMhW8KcEOFmrmsM7LMxFlmhbY82InvrNbRoefbGmc9Rt6KiHvxGH1RVb/SKWTTJMK Ai8hwG+F6sLCo0Fwfsz5Y6FGbe1zGOgTyaElPS1iQVF5484P/MneXQ5HI/9UiUrFlL7F E11ikQ98EJJRUlib85A6sv0ZhPjb6gTl1RqlUvKsrVXlyF7uYNr8s5W7yS3NZFn4c9pw MBXQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=QOKtYm93; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id hg7si9178481ejc.935.2022.02.15.12.03.06; Tue, 15 Feb 2022 12:03:33 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=QOKtYm93; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S243363AbiBOTnh (ORCPT + 99 others); Tue, 15 Feb 2022 14:43:37 -0500 Received: from mxb-00190b01.gslb.pphosted.com ([23.128.96.19]:54658 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234521AbiBOTng (ORCPT ); Tue, 15 Feb 2022 14:43:36 -0500 Received: from mail-yb1-xb33.google.com (mail-yb1-xb33.google.com [IPv6:2607:f8b0:4864:20::b33]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 84F263F882 for ; Tue, 15 Feb 2022 11:43:26 -0800 (PST) Received: by mail-yb1-xb33.google.com with SMTP id 124so31274636ybn.11 for ; Tue, 15 Feb 2022 11:43:26 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=fcf+8o+t6+WnOwFW3ZI0zrWbIEyxTwbnoswnCVbg8F8=; b=QOKtYm93Mb7Nl3MP7JzAntRwnrHs7RWLTU/tCeRP+GM/Jn80ebbb/qwZx5QaX+mewI WUUZuU6nr/9iu5TGPVJhCtVn0+ucVo4HNyV16DQluiaDXFfXynO0wi9IfmRHfy7AMV3Y enPQ2mNYTsv5GfwrdbeHMtTUFex+HrNNLZn/CaLxvTvNAGfSnEUEJgzfZM3ql+B1fRKf Uwxdzq5t7P7l8ohDBs6ISXllYWkYeAtu9rlf3JopT8ubliFCWgGa3QyOd8tlZIIshh/Y beOdvGoM6IwF8SWPlasZQrI4HbcRDD404mYq2HSLETqVVrh8cL4W5EAGq8C3ZQiYQQS/ VPoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=fcf+8o+t6+WnOwFW3ZI0zrWbIEyxTwbnoswnCVbg8F8=; b=RGfXnX9vC6RiCK8tXsrhv9lTZoFsM23fWv9p3oCTXPyKpAjq+SlUHntKjxpMyTkVsZ fJIBJP/ii9o/AaRWPKlPafXV1hQR0BC1eomPw1gHc8Bg6nrKI/0l9I4+P/2+LxDwFUKw MTt5UsrU8mIz9KIh7uxMxuvaK55YpIphIL7Sfpog9/gkMOiYEX0ewBxvUWLRS7TM3QFW fBFbqi8sGHTp9BaFqNBJ4gGtkdid0oUtZV4Ws0s1k2J9opurvG3KEqrTWq1J3zUkSvfx AyMUiRPZZTPmS2SWv+mKA/uI1n0DNBLIVrfM78sibEgRSxJEHclC1BJoGDtDD0MjC3he hn9A== X-Gm-Message-State: AOAM531AbMUTR2GEUc3WpDEN64MeGT9GPzekuo0YpbpGpGt3jSL/Zb0K OCQMECaBLxhfYpm84q8xDVeT5g6qTodUXHNRWdtIfw== X-Received: by 2002:a25:7a47:: with SMTP id v68mr519462ybc.488.1644954205145; Tue, 15 Feb 2022 11:43:25 -0800 (PST) MIME-Version: 1.0 References: <00000000000072ef2c05d7f81950@google.com> In-Reply-To: From: Suren Baghdasaryan Date: Tue, 15 Feb 2022 11:43:14 -0800 Message-ID: Subject: Re: [syzbot] KASAN: use-after-free Read in __oom_reap_task_mm To: Michal Hocko Cc: Yang Shi , syzbot , Andrew Morton , Christian Brauner , Linux Kernel Mailing List , Linux MM , syzkaller-bugs Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-17.6 required=5.0 tests=BAYES_00,DKIMWL_WL_MED, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF, ENV_AND_HDR_SPF_MATCH,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS, T_SCC_BODY_TEXT_LINE,USER_IN_DEF_DKIM_WL,USER_IN_DEF_SPF_WL autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Feb 15, 2022 at 11:36 AM Michal Hocko wrote: > > On Tue 15-02-22 10:10:53, Suren Baghdasaryan wrote: > > On Tue, Feb 15, 2022 at 9:53 AM Yang Shi wrote: > [...] > > > Isn't the below race possible? > > > > > > CPU A CPU B > > > exiting: > > > mmap_write_lock > > > remove_vma() > > > mmap_write_unlock > > > process_mrelease: > > > mmap_read_lock > > > __oom_reap_task_mm > > > mmap_read_unlock > > > > > > > Sure, that sequence (would not call it a race) is possible but in this > > case __oom_reap_task_mm will find no vmas in the mm because exit_mmap > > freed and removed all of them. > > I didn't really have chance to have a closer look but I do not see > exit_mmap doing mm->mmap = NULL so the pointer can be a freed vma unless > I am missing something. I thought we've had it in your patches? Has this > got lost somewhere in the process? Doh! Yes, it looks like I completely missed the actual pointer. That must be it since I don't see any other possibility. Will post a patch shortly. Thanks! > -- > Michal Hocko > SUSE Labs