Re: [PATCH] riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
Paul Walmsley <[email protected]> Wed, 29 Jul 2026 17:37:59 -0600 (MDT)
| Newsgroups | org.infradead.lists.linux-riscv,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 29 Jul 2026, Karl Mehltretter wrote:
> remove_pud_mapping() and remove_p4d_mapping() obtain a child table base
> with pud_offset(p4dp, 0) and p4d_offset(pgd, 0), then add the index for
> addr.
>
> RISC-V folds page-table levels at runtime. When a level is folded, its
> offset helper returns the parent entry itself, but the index can still be
> nonzero. Adding it walks past the parent table. Sv48 folds P4D, while Sv39
> folds both P4D and PUD, so memory hot-remove can descend into unrelated
> memory and pass an invalid page to __free_pages(). This can trigger:
>
> kernel BUG at include/linux/mm.h:1810!
> VM_BUG_ON_PAGE(page_ref_count(page) == 0)
> arch_remove_memory+0x1e/0x5c
> try_remove_memory+0x15e/0x200
> remove_memory+0x24/0x3c
>
> Only add the index when the corresponding page-table level is enabled,
> matching p4d_offset() and pud_offset().
>
> Fixes: c75a74f4ba19 ("riscv: mm: Add memory hotplugging support")
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Karl Mehltretter <[email protected]>
Thanks, queued for v7.2-rc.
- Paul
_______________________________________________
linux-riscv mailing list
[email protected]
http://lists.infradead.org/mailman/listinfo/linux-riscv