Zach O'Keefe
1f12e4b328
mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again
...
commit 9319b647902cbd5cc884ac08a8a6d54ce111fc78 upstream.
(struct dirty_throttle_control *)->thresh is an unsigned long, but is
passed as the u32 divisor argument to div_u64(). On architectures where
unsigned long is 64 bytes, the argument will be implicitly truncated.
Use div64_u64() instead of div_u64() so that the value used in the "is
this a safe division" check is the same as the divisor.
Also, remove redundant cast of the numerator to u64, as that should happen
implicitly.
This would be difficult to exploit in memcg domain, given the ratio-based
arithmetic domain_drity_limits() uses, but is much easier in global
writeback domain with a BDI_CAP_STRICTLIMIT-backing device, using e.g.
vm.dirty_bytes=(1<<32)*PAGE_SIZE so that dtc->thresh == (1<<32)
Link: https://lkml.kernel.org/r/20240118181954.1415197-1-zokeefe@google.com
Fixes: f6789593d5 ("mm/page-writeback.c: fix divide by zero in bdi_dirty_limits()")
Signed-off-by: Zach O'Keefe <zokeefe@google.com>
Cc: Maxim Patlasov <MPatlasov@parallels.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-23 08:25:10 +01:00
..
kasan
panic: Consolidate open-coded panic_on_warn checks
2023-02-06 07:52:50 +01:00
backing-dev.c
mm: bdi: initialize bdi_min_ratio when bdi is unregistered
2021-12-14 14:49:00 +01:00
balloon_compaction.c
cleancache.c
cma.c
mm/cma: use nth_page() in place of direct struct page manipulation
2023-11-28 16:50:19 +00:00
cma.h
cma_debug.c
compaction.c
mm, compaction: fix fast_isolate_around() to stay within boundaries
2023-01-18 11:41:44 +01:00
debug.c
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
failslab.c
filemap.c
mm: allow a controlled amount of unfairness in the page lock
2023-08-30 16:27:26 +02:00
frame_vector.c
v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
2022-12-08 11:23:06 +01:00
frontswap.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
gup.c
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
2022-12-19 12:24:15 +01:00
gup_benchmark.c
highmem.c
hmm.c
huge_memory.c
mm/thp: check and bail out if page in deferred queue already
2023-03-11 16:44:05 +01:00
hugetlb.c
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
2022-12-19 12:24:15 +01:00
hugetlb_cgroup.c
hwpoison-inject.c
init-mm.c
internal.h
interval_tree.c
Kconfig
Kconfig.debug
khugepaged.c
mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma
2023-01-24 07:18:01 +01:00
kmemleak-test.c
kmemleak.c
Revert "mm: kmemleak: take a full lowmem check in kmemleak_*_phys()"
2022-09-15 12:04:49 +02:00
ksm.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
list_lru.c
maccess.c
madvise.c
mm: fix madivse_pageout mishandling on non-LRU page
2022-10-05 10:37:43 +02:00
Makefile
memblock.c
Revert "mm: Always release pages to the buddy allocator in memblock_free_late()."
2023-02-22 12:50:39 +01:00
memcontrol.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
memfd.c
memfd: fix F_SEAL_WRITE after shmem huge page allocated
2022-03-08 19:07:49 +01:00
memory-failure.c
mm/memory-failure: check the mapcount of the precise page
2024-01-15 18:25:27 +01:00
memory.c
mm: fix unmap_mapping_range high bits shift bug
2024-01-15 18:25:28 +01:00
memory_hotplug.c
mempolicy.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
mempool.c
memremap.c
memtest.c
migrate.c
mm/migrate_device.c: flush TLB while holding PTL
2022-10-05 10:37:43 +02:00
mincore.c
mlock.c
mm_init.c
mmap.c
mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region()
2022-09-20 12:28:00 +02:00
mmu_context.c
mmu_gather.c
mm/khugepaged: fix GUP-fast interaction by sending IPI
2022-12-14 11:30:42 +01:00
mmu_notifier.c
mmzone.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
mprotect.c
mremap.c
mm/mremap: hold the rmap lock in write mode when moving page table entries.
2022-08-25 11:17:20 +02:00
msync.c
nommu.c
oom_kill.c
oom_kill.c: futex: delay the OOM reaper to allow time for proper futex cleanup
2022-04-27 13:50:48 +02:00
page-writeback.c
mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again
2024-02-23 08:25:10 +01:00
page_alloc.c
mm/page_alloc: fix potential deadlock on zonelist_update_seq seqlock
2023-05-17 11:36:05 +02:00
page_counter.c
page_ext.c
page_idle.c
page_io.c
mm: fix unexpected zeroed page mapping with zram swap
2022-05-12 12:23:48 +02:00
page_isolation.c
page_owner.c
page_poison.c
page_vma_mapped.c
pagewalk.c
mm: pagewalk: Fix race between unmap and page walker
2022-10-15 07:54:36 +02:00
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
pgtable-generic.c
process_vm_access.c
readahead.c
vfs: fix readahead(2) on block devices
2023-11-20 10:30:08 +01:00
rmap.c
mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse
2022-09-05 10:27:46 +02:00
rodata_test.c
shmem.c
tmpfs: verify {g,u}id mount options correctly
2023-09-23 10:59:40 +02:00
shuffle.c
shuffle.h
slab.c
slab.h
mm: kmemleak: slob: respect SLAB_NOLEAKTRACE flag
2021-11-26 10:47:21 +01:00
slab_common.c
slob.c
slub.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
sparse-vmemmap.c
sparse.c
swap.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
swap_cgroup.c
swap_slots.c
swap_state.c
swapfile.c
mm/swap: fix swap_info_struct race between swapoff and get_swap_pages()
2023-04-20 12:07:35 +02:00
truncate.c
usercopy.c
mm/usercopy: return 1 from hardened_usercopy __setup() handler
2022-04-15 14:18:30 +02:00
userfaultfd.c
mm: userfaultfd: fix missing cache flush in mcopy_atomic_pte() and __mcopy_atomic()
2022-05-15 19:54:47 +02:00
util.c
random: move randomize_page() into mm where it belongs
2022-06-22 14:11:17 +02:00
vmacache.c
vmalloc.c
vmpressure.c
vmscan.c
vmstat.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
workingset.c
z3fold.c
zbud.c
zpool.c
zsmalloc.c
zsmalloc: fix races between asynchronous zspage free and page migration
2022-06-06 08:33:50 +02:00
zswap.c