mm/damon/core.c | 3 +++ 1 file changed, 3 insertions(+)
damon_apply_min_nr_regions() repeatedly split each region until its size
becomes small enough to meet the user-defined low limit of the number of
regions. The loop assumes the split operation (damon_split_region_at())
will always succeed and create the new region. But the operation could
silently fail for memory allocation failures, for example. If such
failure happens and the region was the last region, the linked
list-based next region fetching returns invalid pointer. As a result,
invalid memory dereference and corruption could happen. Fix by breaking
the loop in the corner case.
The allocation failure is unlikely since it is arguably too small to
fail. But, it could still theoretically happen, and the consequence is
very bad.
This issue was discovered [1] by Sashiko.
[1] https://lore.kernel.org/20260717011834.120715-1-sj@kernel.org
Fixes: b1029f29eb1d ("mm/damon/core: split regions for min_nr_regions")
Cc: <stable@vger.kernel.org> # 7.1.x
Signed-off-by: SJ Park <sj@kernel.org>
---
Changes from RFC v1
- RFC v1: https://lore.kernel.org/20260718004301.88883-1-sj@kernel.org
- Drop RFC tag.
- Rebase to latest mm-new.
mm/damon/core.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/mm/damon/core.c b/mm/damon/core.c
index 20d267c615faf..3d829e0ad63b5 100644
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -1913,6 +1913,9 @@ static unsigned long damon_apply_min_nr_regions(struct damon_ctx *ctx)
damon_for_each_region_safe(r, next, t) {
while (damon_sz_region(r) > max_region_sz) {
damon_split_region_at(t, r, max_region_sz);
+ /* split might failed */
+ if (r == damon_last_region(t))
+ break;
r = damon_next_region(r);
}
}
base-commit: 5817557f6220462f0ca298b73e4b3f4bb91ccd1f
--
2.47.3
On Sat, 18 Jul 2026 09:37:06 -0700 SJ Park <sj@kernel.org> wrote: > damon_apply_min_nr_regions() repeatedly split each region until its size > becomes small enough to meet the user-defined low limit of the number of > regions. The loop assumes the split operation (damon_split_region_at()) > will always succeed and create the new region. But the operation could > silently fail for memory allocation failures, for example. If such > failure happens and the region was the last region, the linked > list-based next region fetching returns invalid pointer. As a result, > invalid memory dereference and corruption could happen. Fix by breaking > the loop in the corner case. Sashiko found a room to improve in this patch. I will post a new revision with the improvement. Please don't add this to mm-new. Thanks, SJ [...]
© 2016 - 2026 Red Hat, Inc.