[PATCH v2 0/3] mm: khugepaged: fix tracepoint UAF
Vernon Yang <[email protected]>
| Newsgroups | gmane.linux.kernel,gmane.linux.kernel.mm |
|---|---|
| Message-ID | <[email protected]> |
From: Vernon Yang <[email protected]> The khugepaged tracepoints take a folio pointer and call folio_pfn(), but by then the folio may no longer be valid: freed after folio_put(), folio_unlock() or pte_unmap_unlock(), or not a folio at all but an xarray-encoded swap entry. On classic SPARSEMEM, dereferencing it oopses khugepaged as soon as the trace event is enabled; on other memory models it merely prints a bogus pfn. Pass the pfn to the tracepoints directly, captured while the folio is still pinned, closing the use-after-free windows in mm_khugepaged_scan_file(), mm_khugepaged_scan_pmd() and mm_khugepaged_collapse_file(). V1 -> V2: - Instead of passing the folio, just pass the pfn directly. - Using the folio_pfn() before dropping the reference or the page table lock. V1 : https://lore.kernel.org/linux-mm/[email protected]/ Vernon Yang (3): mm: khugepaged: fix swap entry value to folio_pfn() mm: khugepaged: fix folio is used after pte_unmap_unlock() mm: khugepaged: fix folio is used after folio_put/unlock() include/trace/events/huge_memory.h | 18 +++++++++--------- mm/khugepaged.c | 23 ++++++++++++++++------- 2 files changed, 25 insertions(+), 16 deletions(-) base-commit: 075b74841bd0065a3bda3440873c747938e69b68 -- 2.53.0