Re: [PATCH] riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove

Paul Walmsley <[email protected]> Wed, 29 Jul 2026 17:37:59 -0600 (MDT)
Newsgroups org.infradead.lists.linux-riscv,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Wed, 29 Jul 2026, Karl Mehltretter wrote:

> remove_pud_mapping() and remove_p4d_mapping() obtain a child table base
> with pud_offset(p4dp, 0) and p4d_offset(pgd, 0), then add the index for
> addr.
> 
> RISC-V folds page-table levels at runtime. When a level is folded, its
> offset helper returns the parent entry itself, but the index can still be
> nonzero. Adding it walks past the parent table. Sv48 folds P4D, while Sv39
> folds both P4D and PUD, so memory hot-remove can descend into unrelated
> memory and pass an invalid page to __free_pages(). This can trigger:
> 
>   kernel BUG at include/linux/mm.h:1810!
>   VM_BUG_ON_PAGE(page_ref_count(page) == 0)
>   arch_remove_memory+0x1e/0x5c
>   try_remove_memory+0x15e/0x200
>   remove_memory+0x24/0x3c
> 
> Only add the index when the corresponding page-table level is enabled,
> matching p4d_offset() and pud_offset().
> 
> Fixes: c75a74f4ba19 ("riscv: mm: Add memory hotplugging support")
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Karl Mehltretter <[email protected]>

Thanks, queued for v7.2-rc.


- Paul

_______________________________________________
linux-riscv mailing list
[email protected]
http://lists.infradead.org/mailman/listinfo/linux-riscv