[to-be-updated] mm-page_reporting-use-system_freezable_wq-to-fix-uaf-during-suspend.patch removed from -mm tree
Andrew Morton <[email protected]>
| Newsgroups | org.kernel.vger.mm-commits,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
The quilt patch titled
Subject: mm/page_reporting: use system_freezable_wq to fix UAF during suspend
has been removed from the -mm tree. Its filename was
mm-page_reporting-use-system_freezable_wq-to-fix-uaf-during-suspend.patch
This patch was dropped because an updated version will be issued
------------------------------------------------------
From: Link Lin <[email protected]>
Subject: mm/page_reporting: use system_freezable_wq to fix UAF during suspend
Date: Fri, 17 Jul 2026 00:22:20 +0000
During PM freeze (e.g. S3 suspend or S4 hibernation), device drivers like
virtio_balloon reset their underlying virtio devices and delete their
virtqueues via vdev->config->del_vqs().
However, page reporting work (page_reporting_process) was scheduled on the
global system_wq. Because system_wq lacks the WQ_FREEZABLE flag, the PM
freezer skips it, leaving page_reporting_process active during suspend.
If pages are freed into the buddy allocator while suspending, page
reporting invokes virtballoon_free_page_report() on deleted virtqueues:
[ 196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI
[ 196.825967] Workqueue: events page_reporting_process
[ 196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]
[ 196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]
[ 196.946943] page_reporting_process+0x370/0x4f0
Fix this by switching page reporting work to system_freezable_wq. This
ensures that the PM freezer pauses page_reporting_process before device
drivers destroy their reporting virtqueues.
This aligns with the driver's existing design. The comment in
virtballoon_freeze() states:
/*
* The workqueue is already frozen by the PM core before this
* function is called.
*/
Link: https://lore.kernel.org/[email protected]
Fixes: 924a663f75e2 ("virtio-balloon: Reporting free page reservations")
Signed-off-by: Link Lin <[email protected]>
Suggested-by: David Hildenbrand <[email protected]>
Suggested-by: Michael S. Tsirkin <[email protected]>
Acked-by: Michael S. Tsirkin <[email protected]>
Acked-by: David Hildenbrand (Arm) <[email protected]>
Acked-by: David Rientjes <[email protected]>
Cc: Alexander Duyck <[email protected]>
Cc: Greg Thelen <[email protected]>
Cc: James Houghton <[email protected]>
Cc: Jason Wang <[email protected]>
Cc: Jiaqi Yan <[email protected]>
Cc: Vlastimil Babka <[email protected]>
Cc: Xuan Zhuo <[email protected]>
Cc: <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---
mm/page_reporting.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/mm/page_reporting.c~mm-page_reporting-use-system_freezable_wq-to-fix-uaf-during-suspend
+++ a/mm/page_reporting.c
@@ -81,7 +81,8 @@ __page_reporting_request(struct page_rep
* now we are limiting this to running no more than once every
* couple of seconds.
*/
- schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
+ queue_delayed_work(system_freezable_wq, &prdev->work,
+ PAGE_REPORTING_DELAY);
}
/* notify prdev of free page reporting request */
@@ -341,7 +342,8 @@ err_out:
*/
state = atomic_cmpxchg(&prdev->state, state, PAGE_REPORTING_IDLE);
if (state == PAGE_REPORTING_REQUESTED)
- schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
+ queue_delayed_work(system_freezable_wq, &prdev->work,
+ PAGE_REPORTING_DELAY);
}
static DEFINE_MUTEX(page_reporting_mutex);
_
Patches currently in -mm which might be from [email protected] are
virtio_balloon-avoid-shrinker-execution-during-pm-suspend.patch