From nobody Sat Jul 25 03:05:25 2026 Received: from smtpbguseast2.qq.com (smtpbguseast2.qq.com [54.204.34.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A0B14594A for ; Mon, 20 Jul 2026 08:52:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=54.204.34.130 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784537549; cv=none; b=ZTOREk8mZeMxq30n6B80gBDVbN5vcVlR7w5qARoSq9k9tE2TGT08PNe6vRmwmEuadIR0rgR/letThBNuC/5LMzn7M1sbEGCKTa4kFnJZA4A/53xGvxin0VFYVVwO8pSasraZxzLMJ2D/rc+3sSAnaEabhrxuqmdJCWTLBWWMMDE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784537549; c=relaxed/simple; bh=Hxc4ujGFn4Bici36It2+YybUIAYK5703U+OlaBpAN8k=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=otIyTO31T9ree6VLHqXmpyV5ffItmnevIB/oTbos7BsCxQQCnn+PRf1BqR8EPzP3blhRu0O2AqRLx7xHVHAJakNPf8QXh2Ltm5xjKUO4Ef2gZ6T+/UsBB9sQi2NrhdQJa2uK231wn+rOVFOx2G9ht8GY7wCOE4ZzjrLlk7NinL4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com; spf=pass smtp.mailfrom=uniontech.com; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b=DWqG8oU4; arc=none smtp.client-ip=54.204.34.130 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=uniontech.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b="DWqG8oU4" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=uniontech.com; s=onoh2408; t=1784537434; bh=qwFdiigprnnr+PXeMatxgrhnDGdTJlNK6vXKjM4agmU=; h=From:To:Subject:Date:Message-Id:MIME-Version; b=DWqG8oU4Qm3K3ng2oxPuV6Ajskl91wnEtDu0nsfiPjyLj96XJJF0tev6uqa+Cb/sk mVK92h13cPbajqtywjAt0adYDHCf0vCRdx6vq6mXdMkX19nTyBpLlhpo/DF0MVA9aJ MNs4mpksGTKT7R5reVT6u4SXAwBQ+eSqXRfqvRH0= X-QQ-mid: zesmtpgz5t1784537428ta2b8478f X-QQ-Originating-IP: WbfTXFU/kDf3z6rnhpLug4tdERftmKoz3sfgvejAQsU= Received: from uniontech.com ( [113.57.152.160]) by bizesmtp.qq.com (ESMTP) with id ; Mon, 20 Jul 2026 16:50:25 +0800 (CST) X-QQ-SSF: 0000000000000000000000000000000 X-QQ-GoodBg: 1 X-BIZMAIL-ID: 12259026264893774996 EX-QQ-RecipientCnt: 9 From: Yichong Chen To: Muchun Song , Oscar Salvador Cc: Andrew Morton , David Hildenbrand , Andrew Barry , David Gibson , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Yichong Chen Subject: [PATCH] hugetlb: fix subpool release race Date: Mon, 20 Jul 2026 16:50:24 +0800 Message-Id: <20260720085024.1392261-1-chenyichong@uniontech.com> X-Mailer: git-send-email 2.20.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-QQ-SENDSIZE: 520 Feedback-ID: zesmtpgz:uniontech.com:qybglogicsvrgz:qybglogicsvrgz3a-0 X-QQ-XMAILINFO: M83iEva+1QDBMc0d6gBK3mGcaHttUzu+k8lpp1/PT19Z6x1nIJwEFSbb mRmoTP1bsUQrlO0eYD7jQb6KHdvVDABc95eQcov/LrH1VS0ZL2LigOYm1VxtGBng9DJwR5X rymmlWBeFG2GPjNR1zCVIAwcboB8rxw4v5Jy8SAAy/9p+iZ5AsJ9sGUyISExUU9kD/pRnfW wmW6z7iUIjGFlxUunAgeYdv33CfmwAVLEkmGyT/dOmLxkp229WhTd6leVg2klQU9CkI/1md uRdN3BvsdClxR2ia7MyXvKMoeIelOyw5ppJ+5t3Eypo8FznaiO8/ZKaPvaKeS6tMJsSpNvD A9tQxtjJ4YIkEE5+QPTBSEMQwsqjtJzlj/UrOR6Rzf+vQ3qmibjcAUvnd3QK3Yimgo+BRlk IeFSf4Fz5clfupnC439e8D6zSWKR1I8gbBg0mnmaCfxO7wlfcejw6oU8h5SH9hywZmVtTQx nVRE+F0TmPTeTUa70mfjWIyMbt0gZLgTKNX8q5G59cdylHcVm1/oSl6eJtyE/9Qai5iKh50 OoubDDuL8aYbUI/ItFIEvOYWRPb4IDSVnJxDX9NCpwp2jABOEN2j6Bx49DJmLDUR93ee3C0 oDDGdVIILComINOwSgPbpMGMVhfaCzQfOivaOOJxMTz57KQINu+2Et3i/pmehCf9RYeulUj NeKFjfFwBgZYeFjvkf9q3Ex4kfy+DSsUzz3BhhGdY5I9pZhxIUYgfqshzsV7rGRtDCZlGOO LqY3vHA7AexmTqc7GNvxXIH5tr28cuKOPoqPozs9hDas1zExrDRxapxTC/USuJAtGZ5Fqgz 6BieZ9OdC2Z287MEzqrL4w41gmnQT2ysbSRJQNju1C+QWmVB13aLh40N9nRC5j9qzZ/glvn rxeZmq/99A75Nh7f9iaXeIEC+iGCRE7MCffPdb3vdKJQaX2URDurV9nlcXTcyI+m6xKshck O73j42B/0p4t+i18q7Y7cPd2nVaHq3h9U6sI1vG0K2ZK2HJmpoPBppwvxuItvPa/fwcheHu wBzFaftm9tHXAwWXBVEtiLIW4Fh6Wez26NXRPSEA== X-QQ-XMRINFO: OD9hHCdaPRBwH5bRRRw8tsiH4UAatJqXfg== X-QQ-RECHKSPAM: 0 Content-Type: text/plain; charset="utf-8" unlock_or_release_subpool() drops spool->lock before checking whether the subpool can be freed. However, subpool_is_free() reads fields that are updated under spool->lock, including count, used_hpages and rsv_hpages. Another thread can update those fields before the first thread evaluates subpool_is_free(), allowing both threads to observe the final freeable state and release the subpool. Make the free decision while still holding spool->lock. Keep the actual hugetlb_acct_memory() and kfree() calls after dropping the lock. Fixes: 90481622d757 ("hugepages: fix use after free bug in "quota" handling= ") Signed-off-by: Yichong Chen Reviewed-by: Joshua Hahn --- mm/hugetlb.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/mm/hugetlb.c b/mm/hugetlb.c index e319c6a00555..46ab702c0fc0 100644 --- a/mm/hugetlb.c +++ b/mm/hugetlb.c @@ -140,12 +140,14 @@ static inline bool subpool_is_free(struct hugepage_su= bpool *spool) static inline void unlock_or_release_subpool(struct hugepage_subpool *spoo= l, unsigned long irq_flags) { - spin_unlock_irqrestore(&spool->lock, irq_flags); + bool free_subpool =3D subpool_is_free(spool); =20 /* If no pages are used, and no other handles to the subpool * remain, give up any reservations based on minimum size and * free the subpool */ - if (subpool_is_free(spool)) { + spin_unlock_irqrestore(&spool->lock, irq_flags); + + if (free_subpool) { if (spool->min_hpages !=3D -1) hugetlb_acct_memory(spool->hstate, -spool->min_hpages); --=20 2.51.0