diff --git a/mm/memory.c b/mm/memory.c index 2a633f7284bb..25aaec08c90f 100644 --- a/mm/memory.c +++ b/mm/memory.c @@ -2879,6 +2879,14 @@ static vm_fault_t do_wp_page(struct vm_fault *vmf) { struct vm_area_struct *vma = vmf->vma; + /* + * Userfaultfd write-protect can defer flushes. Ensure the TLB + * is flushed in this case before copying. + */ + if (unlikely(userfaultfd_wp(vmf->vma) && + mm_tlb_flush_pending(vmf->vma->vm_mm))) + flush_tlb_page(vmf->vma, vmf->address); + vmf->page = _vm_normal_page(vma, vmf->address, vmf->orig_pte, vmf->vma_flags); if (!vmf->page) {