Re: [REGRESSION] mm/memcg: folio/lruvec mismatch after cgroup offline: lru_size underflow and list_del corruption (7.1)

Shakeel Butt <[email protected]>
Newsgroups dev.linux.lists.regressions,org.kernel.vger.cgroups,org.kernel.vger.linux-kernel,org.kvack.linux-mm
Message-ID <[email protected]>
On Wed, Aug 05, 2026 at 02:03:03PM +0200, Karl Erik Hofseth wrote:
> Hi,
> 
> The following KASAN slab-use-after-free comes from a Fedora debug kernel
> build of 7.1.6 with de4660898b7a applied on top, provoked with the
> attached script. Further down are OOPSes generated by workloads in
> production on stock Fedora kernels. MGLRU on/off makes no difference.

Hi Karl,

Thanks a lot for the report and I think I understand the issue. We are not
handling the case of folio migration causing folio having objcg different
different from its node which breaks the assumption memcg_reparent_objcgs() have
for its locking lru of child and parent per-node LRUs.

Thanks for the reproducer and I was able to reproduce with inceased workers. I
will send out the fixes soon.

thanks,
Shakeel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.