Received: by 2002:a05:6a10:9afc:0:0:0:0 with SMTP id t28csp119219pxm; Fri, 25 Feb 2022 05:08:20 -0800 (PST) X-Google-Smtp-Source: ABdhPJyu8xsC7t2jU5mLTSsJ5EB4fL3D8amemU0c8KRRKGv6wz/9byuHw9zcEap72SHl01vF/fnJ X-Received: by 2002:a65:64d1:0:b0:374:9f3f:d8f5 with SMTP id t17-20020a6564d1000000b003749f3fd8f5mr6113845pgv.186.1645794500218; Fri, 25 Feb 2022 05:08:20 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1645794500; cv=none; d=google.com; s=arc-20160816; b=wS14LqkRGmEYTsAzh6hbdIHpOoGY6Y5diLJEKGLrHSxgVlZpdgwX+9uZgsA3hFK5v3 OViAb78w1B5MAxPz5d6/qkZKf0jDGit9t8d16KOA1b/n5yUSv4zOGfxVD8GHzdvy4wiI Njeievexg/S4swvWeYSz8Q0eSrIFOEweStKtA6fwctj8H+pyBgmoJfg3yeEG40260Pmm YxTqNkzhviV1gb1usJUZqVh9eNLORugBz1ralqobWP9jpBIbG4I0UPKZfKdcKceEhcXp +NldZRtvOgIMkaYNB/SzpSVLc/44+W0qekpWKgxfVuy70aJ+XNl+A62mPNc0cSHZIUPn svhQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=sLcVCRb+1Z6S+qUcBP1X6RE7IX0nXiVeuQij3kNY+MY=; b=Zt/HEGBrDPVbSbq3DiY6s9VOOJiNsCFh9nC75DEOi/lDQySoZONnLBkGyViHlLU6GD JzVsya3q+t/1wpPud3ITK9s3f2PqiktTFgGcxPviVLFO149dOVTgOks7azk6g+70ntwJ JY1UIgQOQdQCtWB2nOA4SmsOcOlTbmjI8y1N30zudl0kPmdEf/RWbC8V7/EBRfWDK9pz nghPxZRZuTEgDTEj8Ws5bG2yMhlQvFMl8PeaYVrVZI/1KZ21XC8mP7G7L22Sjik8uxVP f89PF2DvzFa6m/A5Vi7hGTWyE23nuZvdzWfqnY/KtObTqBlEst9Ccdq3yMKZk+v+4RtS Sl0g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@suse.com header.s=susede1 header.b=pb0YBCQt; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=suse.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id x21-20020a170902b41500b0014a6d828e96si1738052plr.389.2022.02.25.05.07.54; Fri, 25 Feb 2022 05:08:20 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@suse.com header.s=susede1 header.b=pb0YBCQt; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=suse.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S239372AbiBYKSK (ORCPT + 99 others); Fri, 25 Feb 2022 05:18:10 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:36642 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S239370AbiBYKSJ (ORCPT ); Fri, 25 Feb 2022 05:18:09 -0500 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.220.29]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 7BFB6B2E34 for ; Fri, 25 Feb 2022 02:17:37 -0800 (PST) Received: from relay2.suse.de (relay2.suse.de [149.44.160.134]) by smtp-out2.suse.de (Postfix) with ESMTP id 044C71F383; Fri, 25 Feb 2022 10:17:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=susede1; t=1645784256; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=sLcVCRb+1Z6S+qUcBP1X6RE7IX0nXiVeuQij3kNY+MY=; b=pb0YBCQt38vYZ5wB508BwadF5K806XNyG1wLNJl/9j28n0g8mDYIYpbJjzh3RHfYbtQddp J7nPF7Ymjahnxco/EPRkPTLTf9Vwv+5SfmCig7DenJGwwn9hljHLT7a6+tMp62G5kcvfKu h2DiM2/RH/4BVjJ42pLk3pZdOSaprBo= Received: from suse.cz (unknown [10.100.201.86]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by relay2.suse.de (Postfix) with ESMTPS id A5FF1A3B84; Fri, 25 Feb 2022 10:17:34 +0000 (UTC) Date: Fri, 25 Feb 2022 11:17:34 +0100 From: Michal Hocko To: Andrew Morton Cc: Suren Baghdasaryan , shy828301@gmail.com, rientjes@google.com, willy@infradead.org, hannes@cmpxchg.org, guro@fb.com, riel@surriel.com, minchan@kernel.org, kirill@shutemov.name, aarcange@redhat.com, brauner@kernel.org, christian@brauner.io, hch@infradead.org, oleg@redhat.com, david@redhat.com, jannh@google.com, shakeelb@google.com, luto@kernel.org, christian.brauner@ubuntu.com, fweimer@redhat.com, jengelh@inai.de, timmurray@google.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, kernel-team@android.com, syzbot+2ccf63a4bd07cf39cab0@syzkaller.appspotmail.com, Liam Howlett Subject: Re: [PATCH 1/1] mm: fix use-after-free bug when mm->mmap is reused after being freed Message-ID: References: <20220215201922.1908156-1-surenb@google.com> <20220224201859.a38299b6c9d52cb51e6738ea@linux-foundation.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220224201859.a38299b6c9d52cb51e6738ea@linux-foundation.org> X-Spam-Status: No, score=-4.4 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_MED,SPF_HELO_NONE, SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu 24-02-22 20:18:59, Andrew Morton wrote: > On Tue, 15 Feb 2022 12:19:22 -0800 Suren Baghdasaryan wrote: > > > After exit_mmap frees all vmas in the mm, mm->mmap needs to be reset, > > otherwise it points to a vma that was freed and when reused leads to > > a use-after-free bug. > > > > ... > > > > --- a/mm/mmap.c > > +++ b/mm/mmap.c > > @@ -3186,6 +3186,7 @@ void exit_mmap(struct mm_struct *mm) > > vma = remove_vma(vma); > > cond_resched(); > > } > > + mm->mmap = NULL; > > mmap_write_unlock(mm); > > vm_unacct_memory(nr_accounted); > > } > > After the Maple tree patches, mm_struct.mmap doesn't exist. So I'll > revert this fix as part of merging the maple-tree parts of linux-next. > I'll be sending this fix to Linus this week. But this is a regression introduced in this release cycle so the patch should be merged before Maple tree patches, no? -- Michal Hocko SUSE Labs