Re: KMSAN: use-after-free in sw842_decompress (zswap writeback)
dane phillips <[email protected]> Sat, 1 Aug 2026 23:22:46 -0700
| Newsgroups | org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel,org.kvack.linux-mm |
|---|---|
| Message-ID | <CAAzp_c4_4tVB68P_2EoXP4nLVa7npiHobmTHnjP-aCh0RRKHRA@mail.gmail.com> |
Retracting both of my earlier mails in this thread. There is no bug here, in zswap or in lib/842's input handling, and nobody should spend time on it. I could not reproduce the report; that trace should not have gone out and I'm sorry for the noise. On Fri, Jul 31, 2026 at 8:50=E2=80=AFAM dane phillips <greatdanerrrr@gmail.= com> wrote: > > I got the mechanism wrong in my first mail, correcting before anyone > wastes time on it. > > I read the "Uninit was created at" chain as causal. It isn't. That > chain just says where the page had been before the allocator handed > it back out. exit_mmap has nothing to do with it and there's no race > with process exit. > > The poison is in the compressed input, not in a swapped-out page: > > next_bits+0xac2 lib/842/842_decompress.c:118 > sw842_decompress+0x1a6 lib/842/842_decompress.c:297 > sw842_decompress+0x11c8 lib/842/842_decompress.c:303 > > 297 is the opcode fetch, 303 uses it. > > What I think is happening: zpool_obj_read_begin() copies exactly > entry->length bytes into acomp_ctx->buffer, which is kmalloc'd and > never zeroed, and sw842_decompress reads past entry->length into > whatever was there before. next_bits() does full 8-byte loads while > p->ilen >=3D 8, so entry->length not being a multiple of 8 looks like > the trigger. > > So the subject should be something like "KMSAN: uninit-value in > sw842_decompress, over-read of compressed input past entry->length" > rather than use-after-free. > > Testing that now with kzalloc_node() for the buffer, plus a sweep of > compressed lengths across residues mod 8. Also rerunning with lzo, > zstd and deflate to see whether this is lib/842 or zswap's bounce > buffer. > > Two things I should have mentioned the first time: the kernel was > already tainted W from an unrelated get_xsave_addr warning earlier in > that boot, and the tree was 503 commits past 7.2.0-rc4. I'll redo it > clean on mainline. > > More once I have something. > > Dane > > On Thu, Jul 30, 2026 at 11:20=E2=80=AFAM dane phillips <greatdanerrrr@gma= il.com> wrote: > > > > Hi, > > > > I am running syzkaller on commit 3dab139d4795 and it > > reported the use-after-free below. The issue occurs when zswap > > writeback decompresses a page that has already been freed by > > process exit. > > > > Kernel version: 7.2.0-rc4-00503-g3dab139d4795 > > Config: CONFIG_KMSAN=3Dy, CONFIG_ZSWAP=3Dy, CONFIG_CRYPTO_842=3Dy > > > > The bug manifests in sw842_decompress accessing memory that was > > freed in exit_mmap, while the shrinker is still walking the zswap > > pool. > > > > BUG: KMSAN: use-after-free in sw842_decompress+0x11c8/0x1750 > > lib/842/842_decompress.c:303 > > sw842_decompress+0x11c8/0x1750 lib/842/842_decompress.c:303 > > crypto842_sdecompress+0x46/0x60 crypto/842.c:53 > > scomp_acomp_comp_decomp+0xa49/0x1120 include/crypto/internal/scompress= .h:-1 > > scomp_acomp_decompress+0x30/0x40 crypto/scompress.c:283 > > crypto_acomp_decompress+0x5c4/0xe50 crypto/acompress.c:297 > > zswap_decompress+0x4ba/0xcc0 mm/zswap.c:952 > > zswap_writeback_entry mm/zswap.c:1032 [inline] > > shrink_memcg_cb+0x78f/0xda0 mm/zswap.c:1147 > > __list_lru_walk_one+0x49a/0xde0 mm/list_lru.c:362 > > list_lru_walk_one+0x5c/0x70 mm/list_lru.c:399 > > list_lru_shrink_walk include/linux/list_lru.h:332 [inline] > > zswap_shrinker_scan+0x11f/0x290 mm/zswap.c:1181 > > do_shrink_slab+0x736/0x1460 mm/shrinker.c:443 > > shrink_slab_memcg mm/shrinker.c:560 [inline] > > shrink_slab+0xb70/0x14c0 mm/shrinker.c:638 > > shrink_one+0x560/0xc10 mm/vmscan.c:5026 > > shrink_many mm/vmscan.c:5087 [inline] > > lru_gen_shrink_node mm/vmscan.c:5165 [inline] > > shrink_node+0x47a5/0x5b70 mm/vmscan.c:6154 > > kswapd_shrink_node mm/vmscan.c:7008 [inline] > > balance_pgdat mm/vmscan.c:7186 [inline] > > kswapd+0x3029/0x5a50 mm/vmscan.c:7462 > > kthread+0x53f/0x600 kernel/kthread.c:436 > > ret_from_fork+0x20f/0x8d0 arch/x86/kernel/process.c:158 > > ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 > > > > Uninit was stored to memory at: > > sw842_decompress+0x11c1/0x1750 lib/842/842_decompress.c:303 > > crypto842_sdecompress+0x46/0x60 crypto/842.c:53 > > scomp_acomp_comp_decomp+0xa49/0x1120 include/crypto/internal/scompress= .h:-1 > > scomp_acomp_decompress+0x30/0x40 crypto/scompress.c:283 > > crypto_acomp_decompress+0x5c4/0xe50 crypto/acompress.c:297 > > zswap_decompress+0x4ba/0xcc0 mm/zswap.c:952 > > zswap_writeback_entry mm/zswap.c:1032 [inline] > > shrink_memcg_cb+0x78f/0xda0 mm/zswap.c:1147 > > __list_lru_walk_one+0x49a/0xde0 mm/list_lru.c:362 > > list_lru_walk_one+0x5c/0x70 mm/list_lru.c:399 > > list_lru_shrink_walk include/linux/list_lru.h:332 [inline] > > zswap_shrinker_scan+0x11f/0x290 mm/zswap.c:1181 > > do_shrink_slab+0x736/0x1460 mm/shrinker.c:443 > > shrink_slab_memcg mm/shrinker.c:560 [inline] > > shrink_slab+0xb70/0x14c0 mm/shrinker.c:638 > > shrink_one+0x560/0xc10 mm/vmscan.c:5026 > > shrink_many mm/vmscan.c:5087 [inline] > > lru_gen_shrink_node mm/vmscan.c:5165 [inline] > > shrink_node+0x47a5/0x5b70 mm/vmscan.c:6154 > > kswapd_shrink_node mm/vmscan.c:7008 [inline] > > balance_pgdat mm/vmscan.c:7186 [inline] > > kswapd+0x3029/0x5a50 mm/vmscan.c:7462 > > kthread+0x53f/0x600 kernel/kthread.c:436 > > ret_from_fork+0x20f/0x8d0 arch/x86/kernel/process.c:158 > > ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 > > > > Uninit was stored to memory at: > > next_bits+0xac2/0xda0 lib/842/842_decompress.c:118 > > sw842_decompress+0x1a6/0x1750 lib/842/842_decompress.c:297 > > crypto842_sdecompress+0x46/0x60 crypto/842.c:53 > > scomp_acomp_comp_decomp+0xa49/0x1120 include/crypto/internal/scompress= .h:-1 > > scomp_acomp_decompress+0x30/0x40 crypto/scompress.c:283 > > crypto_acomp_decompress+0x5c4/0xe50 crypto/acompress.c:297 > > zswap_decompress+0x4ba/0xcc0 mm/zswap.c:952 > > zswap_writeback_entry mm/zswap.c:1032 [inline] > > shrink_memcg_cb+0x78f/0xda0 mm/zswap.c:1147 > > __list_lru_walk_one+0x49a/0xde0 mm/list_lru.c:362 > > list_lru_walk_one+0x5c/0x70 mm/list_lru.c:399 > > list_lru_shrink_walk include/linux/list_lru.h:332 [inline] > > zswap_shrinker_scan+0x11f/0x290 mm/zswap.c:1181 > > do_shrink_slab+0x736/0x1460 mm/shrinker.c:443 > > shrink_slab_memcg mm/shrinker.c:560 [inline] > > shrink_slab+0xb70/0x14c0 mm/shrinker.c:638 > > shrink_one+0x560/0xc10 mm/vmscan.c:5026 > > shrink_many mm/vmscan.c:5087 [inline] > > lru_gen_shrink_node mm/vmscan.c:5165 [inline] > > shrink_node+0x47a5/0x5b70 mm/vmscan.c:6154 > > kswapd_shrink_node mm/vmscan.c:7008 [inline] > > balance_pgdat mm/vmscan.c:7186 [inline] > > kswapd+0x3029/0x5a50 mm/vmscan.c:7462 > > kthread+0x53f/0x600 kernel/kthread.c:436 > > ret_from_fork+0x20f/0x8d0 arch/x86/kernel/process.c:158 > > ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 > > > > Uninit was created at: > > __free_pages_prepare mm/page_alloc.c:1327 [inline] > > free_unref_folios+0x280/0x2880 mm/page_alloc.c:3011 > > folios_put_refs+0xb2e/0xba0 mm/swap.c:1057 > > free_pages_and_swap_cache+0x804/0x840 mm/swap_state.c:589 > > __tlb_batch_free_encoded_pages mm/mmu_gather.c:138 [inline] > > tlb_batch_pages_flush mm/mmu_gather.c:151 [inline] > > tlb_flush_mmu_free mm/mmu_gather.c:417 [inline] > > tlb_flush_mmu+0x92b/0xe90 mm/mmu_gather.c:424 > > zap_pte_range mm/memory.c:1973 [inline] > > zap_pmd_range mm/memory.c:2020 [inline] > > zap_pud_range mm/memory.c:2048 [inline] > > zap_p4d_range mm/memory.c:2069 [inline] > > __zap_vma_range+0x763f/0x9340 mm/memory.c:2109 > > unmap_vmas+0x440/0x800 mm/memory.c:2178 > > exit_mmap+0x27c/0xac0 mm/mmap.c:1300 > > __mmput+0x134/0x650 kernel/fork.c:1187 > > mmput+0x74/0x90 kernel/fork.c:1210 > > exit_mm+0x2b1/0x4b0 kernel/exit.c:615 > > do_exit+0x9a9/0x3c30 kernel/exit.c:997 > > do_group_exit+0x258/0x390 kernel/exit.c:1152 > > __do_sys_exit_group kernel/exit.c:1163 [inline] > > __se_sys_exit_group kernel/exit.c:1161 [inline] > > __x64_sys_exit_group+0x35/0x40 kernel/exit.c:1161 > > x64_sys_call+0x3e6d/0x3ea0 arch/x86/include/generated/asm/syscalls_64.= h:232 > > do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] > > do_syscall_64+0x15d/0x3c0 arch/x86/entry/syscall_64.c:94 > > entry_SYSCALL_64_after_hwframe+0x77/0x7f > > > > CPU: 0 UID: 0 PID: 81 Comm: kswapd0 Tainted: G W > > 7.2.0-rc4-00503-g3dab139d4795 #9 PREEMPT(lazy) > > Tainted: [W]=3DWARN > > Hardware name: QEMU Ubuntu 26.04 PC (i440FX + PIIX, 1996), BIOS > > 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014 > > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D > > > > > > > > The full syzkaller log is available if needed. I do not yet have a > > reliable reproducer. > > > > Thanks, > > > > Dane Phillips