[to-be-updated] mm-page_reporting-use-system_freezable_wq-to-fix-uaf-during-suspend.patch removed from -mm tree

Andrew Morton <[email protected]>
Newsgroups org.kernel.vger.mm-commits,org.kernel.vger.stable
Message-ID <[email protected]>
The quilt patch titled
     Subject: mm/page_reporting: use system_freezable_wq to fix UAF during suspend
has been removed from the -mm tree.  Its filename was
     mm-page_reporting-use-system_freezable_wq-to-fix-uaf-during-suspend.patch

This patch was dropped because an updated version will be issued

------------------------------------------------------
From: Link Lin <[email protected]>
Subject: mm/page_reporting: use system_freezable_wq to fix UAF during suspend
Date: Fri, 17 Jul 2026 00:22:20 +0000

During PM freeze (e.g.  S3 suspend or S4 hibernation), device drivers like
virtio_balloon reset their underlying virtio devices and delete their
virtqueues via vdev->config->del_vqs().

However, page reporting work (page_reporting_process) was scheduled on the
global system_wq.  Because system_wq lacks the WQ_FREEZABLE flag, the PM
freezer skips it, leaving page_reporting_process active during suspend. 
If pages are freed into the buddy allocator while suspending, page
reporting invokes virtballoon_free_page_report() on deleted virtqueues:

    [  196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI
    [  196.825967] Workqueue: events page_reporting_process
    [  196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]
    [  196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]
    [  196.946943] page_reporting_process+0x370/0x4f0

Fix this by switching page reporting work to system_freezable_wq.  This
ensures that the PM freezer pauses page_reporting_process before device
drivers destroy their reporting virtqueues.

This aligns with the driver's existing design. The comment in
virtballoon_freeze() states:
    /*
     * The workqueue is already frozen by the PM core before this
     * function is called.
     */

Link: https://lore.kernel.org/[email protected]
Fixes: 924a663f75e2 ("virtio-balloon: Reporting free page reservations")
Signed-off-by: Link Lin <[email protected]>
Suggested-by: David Hildenbrand <[email protected]>
Suggested-by: Michael S. Tsirkin <[email protected]>
Acked-by: Michael S. Tsirkin <[email protected]>
Acked-by: David Hildenbrand (Arm) <[email protected]>
Acked-by: David Rientjes <[email protected]>
Cc: Alexander Duyck <[email protected]>
Cc: Greg Thelen <[email protected]>
Cc: James Houghton <[email protected]>
Cc: Jason Wang <[email protected]>
Cc: Jiaqi Yan <[email protected]>
Cc: Vlastimil Babka <[email protected]>
Cc: Xuan Zhuo <[email protected]>
Cc: <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---

 mm/page_reporting.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/mm/page_reporting.c~mm-page_reporting-use-system_freezable_wq-to-fix-uaf-during-suspend
+++ a/mm/page_reporting.c
@@ -81,7 +81,8 @@ __page_reporting_request(struct page_rep
 	 * now we are limiting this to running no more than once every
 	 * couple of seconds.
 	 */
-	schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
+	queue_delayed_work(system_freezable_wq, &prdev->work,
+			   PAGE_REPORTING_DELAY);
 }
 
 /* notify prdev of free page reporting request */
@@ -341,7 +342,8 @@ err_out:
 	 */
 	state = atomic_cmpxchg(&prdev->state, state, PAGE_REPORTING_IDLE);
 	if (state == PAGE_REPORTING_REQUESTED)
-		schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
+		queue_delayed_work(system_freezable_wq, &prdev->work,
+				   PAGE_REPORTING_DELAY);
 }
 
 static DEFINE_MUTEX(page_reporting_mutex);
_

Patches currently in -mm which might be from [email protected] are

virtio_balloon-avoid-shrinker-execution-during-pm-suspend.patch
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.