Miaohe Lin
25f506273b
mm/mempolicy: fix mpol_new leak in shared_policy_replace
...
commit 4ad099559b00ac01c3726e5c95dc3108ef47d03e upstream.
If mpol_new is allocated but not used in restart loop, mpol_new will be
freed via mpol_put before returning to the caller. But refcnt is not
initialized yet, so mpol_put could not do the right things and might
leak the unused mpol_new. This would happen if mempolicy was updated on
the shared shmem file while the sp->lock has been dropped during the
memory allocation.
This issue could be triggered easily with the below code snippet if
there are many processes doing the below work at the same time:
shmid = shmget((key_t)5566, 1024 * PAGE_SIZE, 0666|IPC_CREAT);
shm = shmat(shmid, 0, 0);
loop many times {
mbind(shm, 1024 * PAGE_SIZE, MPOL_LOCAL, mask, maxnode, 0);
mbind(shm + 128 * PAGE_SIZE, 128 * PAGE_SIZE, MPOL_DEFAULT, mask,
maxnode, 0);
}
Link: https://lkml.kernel.org/r/20220329111416.27954-1-linmiaohe@huawei.com
Fixes: 42288fe366 ("mm: mempolicy: Convert shared_policy mutex to spinlock")
Signed-off-by: Miaohe Lin <linmiaohe@huawei.com>
Acked-by: Michal Hocko <mhocko@suse.com>
Cc: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com>
Cc: Mel Gorman <mgorman@suse.de>
Cc: <stable@vger.kernel.org> [3.8]
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-15 14:18:39 +02:00
..
kasan
kasan: fix incorrect arguments passing in kasan_add_zero_shadow
2021-01-27 11:47:53 +01:00
backing-dev.c
mm: bdi: initialize bdi_min_ratio when bdi is unregistered
2021-12-14 14:49:00 +01:00
balloon_compaction.c
cleancache.c
cma.c
cma: don't quit at first error when activating reserved areas
2020-09-03 11:26:51 +02:00
cma.h
cma_debug.c
compaction.c
mm/compaction: fix misbehaviors of fast_find_migrateblock()
2021-03-04 10:26:39 +01:00
debug.c
mm/debug.c: always print flags in dump_page()
2020-03-05 16:43:51 +01:00
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
failslab.c
filemap.c
mm/filemap: fix storing to a THP shadow entry
2021-06-10 13:37:15 +02:00
frame_vector.c
frontswap.c
gup.c
mm/gup: fix gup_fast with dynamic page table folding
2020-10-01 13:18:24 +02:00
gup_benchmark.c
highmem.c
hmm.c
huge_memory.c
mm/huge_memory.c: don't discard hugepage if other processes are mapping it
2021-07-14 16:53:47 +02:00
hugetlb.c
hugetlbfs: flush TLBs correctly after huge_pmd_unshare
2021-11-26 10:47:23 +01:00
hugetlb_cgroup.c
hwpoison-inject.c
init-mm.c
internal.h
mm/thp: fix vma_address() if virtual address below file offset
2021-06-30 08:47:52 -04:00
interval_tree.c
Kconfig
mm/zsmalloc.c: drop ZSMALLOC_PGTABLE_MAPPING
2020-12-16 10:56:59 +01:00
Kconfig.debug
khugepaged.c
khugepaged: fix wrong result value for trace_mm_collapse_huge_page_isolate()
2021-05-19 10:08:27 +02:00
kmemleak-test.c
kmemleak.c
mm/kmemleak: reset tag when compare object pointer
2022-04-15 14:18:01 +02:00
ksm.c
ksm: fix potential missing rmap_item for stable_node
2021-05-19 10:08:27 +02:00
list_lru.c
mm: list_lru: set shrinker map bit when child nr_items is not zero
2020-12-11 13:23:31 +01:00
maccess.c
madvise.c
mm: validate pmd after splitting
2020-10-01 13:18:21 +02:00
Makefile
memblock.c
memblock: use kfree() to release kmalloced memblock regions
2022-03-02 11:41:18 +01:00
memcontrol.c
mm/memcontrol: return 1 from cgroup.memory __setup() handler
2022-04-15 14:18:29 +02:00
memfd.c
memfd: fix F_SEAL_WRITE after shmem huge page allocated
2022-03-08 19:07:49 +01:00
memory-failure.c
mm/memory-failure: make sure wait for page writeback in memory_failure
2021-06-23 14:41:23 +02:00
memory.c
mm,hwpoison: unmap poisoned page before invalidation
2022-04-15 14:18:01 +02:00
memory_hotplug.c
mm/memory_hotplug: use "unsigned long" for PFN in zone_for_pfn_range()
2021-09-22 12:26:43 +02:00
mempolicy.c
mm/mempolicy: fix mpol_new leak in shared_policy_replace
2022-04-15 14:18:39 +02:00
mempool.c
memremap.c
memtest.c
migrate.c
mm, thp: use head page in __migration_entry_wait()
2021-06-30 08:47:52 -04:00
mincore.c
mlock.c
mm_init.c
mmap.c
mm/mmap: return 1 from stack_guard_gap __setup() handler
2022-04-15 14:18:29 +02:00
mmu_context.c
mm: fix kthread_use_mm() vs TLB invalidate
2020-09-03 11:26:51 +02:00
mmu_gather.c
mm/mmu_gather: invalidate TLB correctly on batch allocation failure and flush
2020-02-11 04:35:42 -08:00
mmu_notifier.c
mmzone.c
mprotect.c
mm, numa: fix bad pmd by atomically check for pmd_trans_huge when marking page tables prot_numa
2020-03-12 13:00:19 +01:00
mremap.c
mmmremap.c: avoid pointless invalidate_range_start/end on mremap(old_size=0)
2022-04-15 14:18:39 +02:00
msync.c
nommu.c
x86/mm: split vmalloc_sync_all()
2020-03-25 08:25:58 +01:00
oom_kill.c
mm, oom: do not trigger out_of_memory from the #PF
2021-11-17 09:48:50 +01:00
page-writeback.c
page_alloc.c
mm/pages_alloc.c: don't create ZONE_MOVABLE beyond the end of a node
2022-04-15 14:18:00 +02:00
page_counter.c
mm/page_counter.c: fix protection usage propagation
2020-08-21 13:05:27 +02:00
page_ext.c
page_idle.c
page_io.c
swap: fix swapfile read/write offset
2021-03-07 12:20:49 +01:00
page_isolation.c
mm/memory_hotplug: drain per-cpu pages again during memory offline
2020-09-23 12:40:47 +02:00
page_owner.c
mm/page_owner: change split_page_owner to take a count
2020-10-29 09:57:52 +01:00
page_poison.c
page_vma_mapped.c
mm/thp: another PVMW_SYNC fix in page_vma_mapped_walk()
2021-06-30 08:47:55 -04:00
pagewalk.c
mm: pagewalk: fix termination condition in walk_pte_range()
2020-10-01 13:17:30 +02:00
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
percpu: fix first chunk size calculation for populated bitmap
2020-09-23 12:40:45 +02:00
pgtable-generic.c
mm/thp: fix __split_huge_pmd_locked() on shmem migration entry
2021-06-30 08:47:52 -04:00
process_vm_access.c
readahead.c
rmap.c
mm: fix race between MADV_FREE reclaim and blkdev direct IO read
2022-04-15 14:18:36 +02:00
rodata_test.c
shmem.c
shmem: fix a race between shmem_unused_huge_shrink and shmem_evict_inode
2022-01-27 09:19:29 +01:00
shuffle.c
mm/shuffle: don't move pages between zones and don't read garbage memmaps
2020-09-03 11:26:51 +02:00
shuffle.h
slab.c
slab.h
mm: kmemleak: slob: respect SLAB_NOLEAKTRACE flag
2021-11-26 10:47:21 +01:00
slab_common.c
mm: slab: fix kmem_cache_create failed when sysfs node not destroyed
2021-07-25 14:35:14 +02:00
slob.c
slub.c
mm, slub: fix potential memoryleak in kmem_cache_open()
2021-10-27 09:54:28 +02:00
sparse-vmemmap.c
sparse.c
mm/sparse: add the missing sparse_buffer_fini() in error branch
2021-05-14 09:44:32 +02:00
swap.c
swap_cgroup.c
swap_slots.c
swap_state.c
mm/swap_state: fix a data race in swapin_nr_pages
2020-10-01 13:18:08 +02:00
swapfile.c
swap: fix swapfile read/write offset
2021-03-07 12:20:49 +01:00
truncate.c
mm/thp: unmap_mapping_page() to fix THP truncate_cleanup_page()
2021-06-30 08:47:53 -04:00
usercopy.c
mm/usercopy: return 1 from hardened_usercopy __setup() handler
2022-04-15 14:18:30 +02:00
userfaultfd.c
hugetlbfs: hugetlb_fault_mutex_hash() cleanup
2021-03-30 14:35:19 +02:00
util.c
mm: add kvfree_sensitive() for freeing sensitive data objects
2020-06-17 16:40:23 +02:00
vmacache.c
vmalloc.c
mm/vunmap: add cond_resched() in vunmap_pmd_range
2020-09-03 11:26:52 +02:00
vmpressure.c
vmscan.c
mm,vmscan: fix divide by zero in get_scan_count
2021-09-22 12:26:37 +02:00
vmstat.c
workingset.c
z3fold.c
mm/z3fold: fix potential memory leak in z3fold_destroy_pool()
2021-07-14 16:53:47 +02:00
zbud.c
zpool.c
zsmalloc.c
mm/zsmalloc.c: close race window between zs_pool_dec_isolated() and zs_unregister_migration()
2021-11-17 09:48:47 +01:00
zswap.c