gaoxiang17
75dbc029c5
pid: Add a judgment for ns null in pid_nr_ns
[ Upstream commit 006568ab4c5ca2309ceb36fa553e390b4aa9c0c7 ]
__task_pid_nr_ns
ns = task_active_pid_ns(current);
pid_nr_ns(rcu_dereference(*task_pid_ptr(task, type)), ns);
if (pid && ns->level <= pid->level) {
Sometimes null is returned for task_active_pid_ns. Then it will trigger kernel panic in pid_nr_ns.
For example:
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000058
Mem abort info:
ESR = 0x0000000096000007
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x07: level 3 translation fault
Data abort info:
ISV = 0, ISS = 0x00000007, ISS2 = 0x00000000
CM = 0, WnR = 0, TnD = 0, TagAccess = 0
GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
user pgtable: 4k pages, 39-bit VAs, pgdp=00000002175aa000
[0000000000000058] pgd=08000002175ab003, p4d=08000002175ab003, pud=08000002175ab003, pmd=08000002175be003, pte=0000000000000000
pstate: 834000c5 (Nzcv daIF +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : __task_pid_nr_ns+0x74/0xd0
lr : __task_pid_nr_ns+0x24/0xd0
sp : ffffffc08001bd10
x29: ffffffc08001bd10 x28: ffffffd4422b2000 x27: 0000000000000001
x26: ffffffd442821168 x25: ffffffd442821000 x24: 00000f89492eab31
x23: 00000000000000c0 x22: ffffff806f5693c0 x21: ffffff806f5693c0
x20: 0000000000000001 x19: 0000000000000000 x18: 0000000000000000
x17: 00000000529c6ef0 x16: 00000000529c6ef0 x15: 00000000023a1adc
x14: 0000000000000003 x13: 00000000007ef6d8 x12: 001167c391c78800
x11: 00ffffffffffffff x10: 0000000000000000 x9 : 0000000000000001
x8 : ffffff80816fa3c0 x7 : 0000000000000000 x6 : 49534d702d535449
x5 : ffffffc080c4c2c0 x4 : ffffffd43ee128c8 x3 : ffffffd43ee124dc
x2 : 0000000000000000 x1 : 0000000000000001 x0 : ffffff806f5693c0
Call trace:
__task_pid_nr_ns+0x74/0xd0
...
__handle_irq_event_percpu+0xd4/0x284
handle_irq_event+0x48/0xb0
handle_fasteoi_irq+0x160/0x2d8
generic_handle_domain_irq+0x44/0x60
gic_handle_irq+0x4c/0x114
call_on_irq_stack+0x3c/0x74
do_interrupt_handler+0x4c/0x84
el1_interrupt+0x34/0x58
el1h_64_irq_handler+0x18/0x24
el1h_64_irq+0x68/0x6c
account_kernel_stack+0x60/0x144
exit_task_stack_account+0x1c/0x80
do_exit+0x7e4/0xaf8
...
get_signal+0x7bc/0x8d8
do_notify_resume+0x128/0x828
el0_svc+0x6c/0x70
el0t_64_sync_handler+0x68/0xbc
el0t_64_sync+0x1a8/0x1ac
Code: 35fffe54 911a02a8 f9400108 b4000128 (b9405a69)
---[ end trace 0000000000000000 ]---
Kernel panic - not syncing: Oops: Fatal exception in interrupt
Signed-off-by: gaoxiang17 <gaoxiang17@xiaomi.com>
Link: https://lore.kernel.org/20250802022123.3536934-1-gxxa03070307@gmail.com
Reviewed-by: Baoquan He <bhe@redhat.com>
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2025-10-29 13:59:55 +01:00 |
| .. |
|
bpf
|
bpf: fix potential error return
|
2025-01-09 13:23:36 +01:00 |
|
cgroup
|
cgroup: split cgroup_destroy_wq into 3 workqueues
|
2025-10-02 13:34:30 +02:00 |
|
configs
|
|
|
|
debug
|
kdb: Use the passed prompt in kdb_position_cursor()
|
2024-08-19 05:33:40 +02:00 |
|
dma
|
dma: fix call order in dmam_free_coherent
|
2024-08-19 05:33:41 +02:00 |
|
events
|
perf/core: Prevent VMA split of buffer mappings
|
2025-08-28 16:21:23 +02:00 |
|
gcov
|
gcov: add support for GCC 14
|
2024-07-05 09:08:24 +02:00 |
|
irq
|
genirq: Provide new interfaces for affinity hints
|
2025-10-02 13:34:29 +02:00 |
|
livepatch
|
livepatch: fix race between fork and KLP transition
|
2022-10-26 13:22:18 +02:00 |
|
locking
|
locking/lockdep: Decrease nr_unused_locks if lock unused in zap_class()
|
2025-05-02 07:39:15 +02:00 |
|
power
|
PM: sleep: console: Fix the black screen issue
|
2025-08-28 16:21:25 +02:00 |
|
printk
|
printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
|
2025-03-13 12:43:02 +01:00 |
|
rcu
|
rcu: Protect ->defer_qs_iw_pending from data race
|
2025-08-28 16:21:26 +02:00 |
|
sched
|
cpufreq/sched: Explicitly synchronize limits_changed flag handling
|
2025-09-09 18:44:00 +02:00 |
|
time
|
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
|
2025-06-27 11:02:57 +01:00 |
|
trace
|
tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
|
2025-10-29 13:59:55 +01:00 |
|
.gitignore
|
|
|
|
acct.c
|
acct: perform last write from workqueue
|
2025-03-13 12:43:26 +01:00 |
|
async.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
audit.c
|
audit: Send netlink ACK before setting connection in auditd_set
|
2024-02-23 08:24:54 +01:00 |
|
audit.h
|
audit: log AUDIT_TIME_* records only from rules
|
2022-04-15 14:18:04 +02:00 |
|
audit_fsnotify.c
|
audit: fix potential double free on error path from fsnotify_add_inode_mark
|
2022-09-05 10:27:38 +02:00 |
|
audit_tree.c
|
audit: move put_tree() to avoid trim_trees refcount underflow and UAF
|
2021-09-03 10:08:16 +02:00 |
|
audit_watch.c
|
audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
|
2023-11-28 16:50:18 +00:00 |
|
auditfilter.c
|
|
|
|
auditsc.c
|
audit: fix possible soft lockup in __audit_inode_child()
|
2023-09-23 10:59:46 +02:00 |
|
backtracetest.c
|
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
|
2023-04-20 12:07:32 +02:00 |
|
bounds.c
|
bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
|
2024-05-02 16:18:37 +02:00 |
|
capability.c
|
|
|
|
compat.c
|
sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
|
2023-04-05 11:16:42 +02:00 |
|
configs.c
|
|
|
|
context_tracking.c
|
|
|
|
cpu.c
|
hrtimers: Handle CPU state correctly on hotplug
|
2025-02-01 18:18:51 +01:00 |
|
cpu_pm.c
|
|
|
|
crash_core.c
|
|
|
|
crash_dump.c
|
|
|
|
cred.c
|
cred: switch to using atomic_long_t
|
2023-12-20 15:41:18 +01:00 |
|
delayacct.c
|
|
|
|
dma.c
|
|
|
|
exec_domain.c
|
|
|
|
exit.c
|
perf: Fix sample vs do_exit()
|
2025-06-27 11:02:58 +01:00 |
|
extable.c
|
kernel/extable.c: use address-of operator on section symbols
|
2023-06-09 10:29:01 +02:00 |
|
fail_function.c
|
kernel/fail_function: fix memory leak with using debugfs_lookup()
|
2023-03-11 16:44:15 +01:00 |
|
fork.c
|
mm: drop the assumption that VM_SHARED always implies writable
|
2025-08-28 16:21:36 +02:00 |
|
freezer.c
|
|
|
|
futex.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
gen_kheaders.sh
|
kheaders: Ignore silly-rename files
|
2025-02-01 18:18:51 +01:00 |
|
groups.c
|
|
|
|
hung_task.c
|
|
|
|
iomem.c
|
|
|
|
irq_work.c
|
|
|
|
jump_label.c
|
|
|
|
kallsyms.c
|
|
|
|
kcmp.c
|
|
|
|
Kconfig.freezer
|
|
|
|
Kconfig.hz
|
|
|
|
Kconfig.locks
|
|
|
|
Kconfig.preempt
|
|
|
|
kcov.c
|
|
|
|
kexec.c
|
|
|
|
kexec_core.c
|
kexec: fix a memory leak in crash_shrink_memory()
|
2023-07-27 08:37:10 +02:00 |
|
kexec_elf.c
|
kexec: initialize ELF lowest address to ULONG_MAX
|
2025-04-10 14:29:41 +02:00 |
|
kexec_file.c
|
kexec: support purgatories with .text.hot sections
|
2023-06-21 15:44:10 +02:00 |
|
kexec_internal.h
|
|
|
|
kheaders.c
|
kheaders: Use array declaration instead of char
|
2023-05-17 11:35:33 +02:00 |
|
kmod.c
|
|
|
|
kprobes.c
|
kprobes: Fix possible use-after-free issue on kprobe registration
|
2024-05-02 16:18:30 +02:00 |
|
ksysfs.c
|
|
|
|
kthread.c
|
kthread: fix task state in kthread worker if being frozen
|
2024-11-08 16:20:30 +01:00 |
|
latencytop.c
|
|
|
|
Makefile
|
|
|
|
module-internal.h
|
|
|
|
module.c
|
modules: only allow symbol_get of EXPORT_SYMBOL_GPL modules
|
2023-09-23 10:59:36 +02:00 |
|
module_signature.c
|
|
|
|
module_signing.c
|
|
|
|
notifier.c
|
|
|
|
nsproxy.c
|
|
|
|
padata.c
|
padata: fix sysfs store callback check
|
2025-03-13 12:42:56 +01:00 |
|
panic.c
|
panic: Flush kernel log buffer at the end
|
2024-04-13 12:51:37 +02:00 |
|
params.c
|
module: ensure that kobject_put() is safe for module type kobjects
|
2025-06-04 14:32:27 +02:00 |
|
pid.c
|
pid: Add a judgment for ns null in pid_nr_ns
|
2025-10-29 13:59:55 +01:00 |
|
pid_namespace.c
|
memcg: enable accounting for pids in nested pid namespaces
|
2021-09-22 12:26:37 +02:00 |
|
profile.c
|
profiling: fix shift too large makes kernel panic
|
2022-08-25 11:18:02 +02:00 |
|
ptrace.c
|
ptrace: Reimplement PTRACE_KILL by always sending SIGKILL
|
2022-06-14 18:11:24 +02:00 |
|
range.c
|
|
|
|
reboot.c
|
kernel/reboot: emergency_restart: Set correct system_state
|
2023-11-28 16:50:19 +00:00 |
|
relay.c
|
relayfs: fix out-of-bounds access in relay_file_read
|
2023-05-17 11:35:58 +02:00 |
|
resource.c
|
resource: fix region_intersects() vs add_memory_driver_managed()
|
2024-11-08 16:20:46 +01:00 |
|
rseq.c
|
|
|
|
seccomp.c
|
seccomp: Invalidate seccomp mode to catch death failures
|
2022-02-16 12:52:53 +01:00 |
|
signal.c
|
signal: Replace BUG_ON()s
|
2024-11-08 16:20:38 +01:00 |
|
smp.c
|
smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
|
2024-09-12 11:03:54 +02:00 |
|
smpboot.c
|
|
|
|
smpboot.h
|
|
|
|
softirq.c
|
tasklet: Introduce new initialization API
|
2025-03-13 12:43:04 +01:00 |
|
stackleak.c
|
|
|
|
stacktrace.c
|
|
|
|
stop_machine.c
|
|
|
|
sys.c
|
getrusage: use sig->stats_lock rather than lock_task_sighand()
|
2024-03-15 10:48:19 -04:00 |
|
sys_ni.c
|
kernel/sys_ni: add compat entry for fadvise64_64
|
2022-09-05 10:27:38 +02:00 |
|
sysctl-test.c
|
|
|
|
sysctl.c
|
sched/rt: Disallow writing invalid values to sched_rt_period_us
|
2024-03-01 13:13:33 +01:00 |
|
sysctl_binary.c
|
|
|
|
task_work.c
|
|
|
|
taskstats.c
|
|
|
|
test_kprobes.c
|
|
|
|
torture.c
|
|
|
|
tracepoint.c
|
|
|
|
tsacct.c
|
taskstats: Cleanup the use of task->exit_code
|
2022-02-23 11:59:57 +01:00 |
|
ucount.c
|
|
|
|
uid16.c
|
|
|
|
uid16.h
|
|
|
|
umh.c
|
|
|
|
up.c
|
|
|
|
user-return-notifier.c
|
|
|
|
user.c
|
|
|
|
user_namespace.c
|
|
|
|
utsname.c
|
|
|
|
utsname_sysctl.c
|
|
|
|
watchdog.c
|
watchdog: export lockup_detector_reconfigure
|
2022-08-25 11:18:37 +02:00 |
|
watchdog_hld.c
|
watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
|
2024-08-19 05:33:39 +02:00 |
|
workqueue.c
|
workqueue: Override implicit ordered attribute in workqueue_apply_unbound_cpumask()
|
2023-10-25 11:53:18 +02:00 |
|
workqueue_internal.h
|
|
|