From nobody Mon Sep 28 09:59:44 2026 Received: from canpmsgout04.his.huawei.com (canpmsgout04.his.huawei.com [113.46.200.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 41A9334E75A for ; Mon, 24 Aug 2026 03:39:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.219 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787542771; cv=none; b=Gwh+JLSL1oGHQsxM5a93Z17XQLRj2bh5aGvcXi03329xMTc1clMHqBQtAaJ7EPbtd9+kof/U6UDSFWQtAizN25G5GrbOB2uFz2V4KlnjEd+ghMXSy6Q6BxkGA1e0r8asNeULcPqF5DaxKCxc1NvTy5aErOoVtO/9wiacYXPWPQY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787542771; c=relaxed/simple; bh=Y0eu3qNNUjLB8UnUe7zg4aOm3vxzmOpTHxGe5AHizNk=; h=From:To:CC:Subject:Date:Message-ID:MIME-Version:Content-Type; b=OOz/Ps0R087uutL2UgJU7UlJ37dqVbNma7Ksx2gWqXR9aHIfPFo85J0E3YOX1j4+nXdQABe7ko3WufaKPKYgdD9pQdAhFjOFNSOQuqh3Eh6VdZekXeYvcbfKlBJrUejjFAQo0dOisKSpKz24T6jHlC9HiKq38qYL/GxGy4tZXzc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=HEiigtRy; arc=none smtp.client-ip=113.46.200.219 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="HEiigtRy" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=S0XMV8dDjyjD8idM+hvibrHGWRV343o2zdvhgJxRvsI=; b=HEiigtRyqsTYMkPiUSa78EzSahoQzDXUY2mbkceahmykmV0xYHEIVHXFBate7xBGcV7IFNdMN FAKRVVigdOw8YYJUH/DmzEzCEdyfqFe8+lUiQoNleTTjwKCVnIZfDcSFuiD6lFqkvO1Pt8HsI69 faxDd9Eqot3PGaLBIwCVa9w= Received: from mail.maildlp.com (unknown [172.19.163.104]) by canpmsgout04.his.huawei.com (SkyGuard) with ESMTPS id 4hSxFt0K8Cz1prN4; Mon, 24 Aug 2026 11:28:34 +0800 (CST) Received: from dggpemr500006.china.huawei.com (unknown [7.185.36.185]) by mail.maildlp.com (Postfix) with ESMTPS id 414914057F; Mon, 24 Aug 2026 11:39:20 +0800 (CST) Received: from localhost.localdomain (10.50.85.180) by dggpemr500006.china.huawei.com (7.185.36.185) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Mon, 24 Aug 2026 11:39:19 +0800 From: Yao Kai To: , CC: , Subject: [PATCH] workqueue: Fix unbound pool lifetime for pending pwqs Date: Mon, 24 Aug 2026 11:58:52 +0800 Message-ID: <20260824035852.2727765-1-yaokai34@huawei.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems100002.china.huawei.com (7.221.188.206) To dggpemr500006.china.huawei.com (7.185.36.185) Content-Type: text/plain; charset="utf-8" KASAN reports a use-after-free of an unbound worker_pool in node_activate_pending_pwq(): BUG: KASAN: slab-use-after-free in _raw_spin_trylock+0x6d/0x120 Read of size 4 at addr ffff8880089ce000 by task kworker/u22:0/318 CPU: 1 UID: 0 PID: 318 Comm: kworker/u22:0 Not tainted 7.2.0 #1 PREEMPT(l= azy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/0= 1/2014 Workqueue: 0x0 (flush-8:0) Call Trace: dump_stack_lvl+0x53/0x70 print_report+0xce/0x610 kasan_report+0xce/0x100 _raw_spin_trylock+0x6d/0x120 pwq_dec_nr_in_flight+0x4b4/0xcb0 process_one_work+0x921/0x11a0 worker_thread+0x4d0/0xd20 kthread+0x2de/0x3c0 ret_from_fork+0x3aa/0x620 ret_from_fork_asm+0x1a/0x30 Allocated by task 311: alloc_pwq+0x439/0xca0 apply_wqattrs_prepare+0x75e/0xd10 apply_workqueue_attrs_locked+0x44/0xa0 wq_nice_store+0x350/0x450 Freed by task 0: kfree+0x127/0x3b0 rcu_core+0x523/0x1780 handle_softirqs+0x1b3/0x610 Last potentially related work creation: put_unbound_pool+0x3f3/0x7d0 pwq_release_workfn+0x494/0x8e0 kthread_worker_fn+0x1ff/0x790 Canceling the last inactive work skips pwq_dec_nr_active(), so an empty pwq can remain on pending_pwqs when its refcnt reaches zero. pwq_release_workfn() currently puts the pool before removing that pwq. If this drops the last pool reference, the pool can be RCU-freed while the pwq remains reachable, and node_activate_pending_pwq() may trylock the freed pool->lock. Remove the pwq from pending_pwqs before putting the pool. Fixes: 5797b1c18919 ("workqueue: Implement system-wide nr_active enforcemen= t for unbound workqueues") Cc: stable@vger.kernel.org Signed-off-by: Yao Kai --- kernel/workqueue.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/kernel/workqueue.c b/kernel/workqueue.c index bfeef512f6dd..a0ca9d83c513 100644 --- a/kernel/workqueue.c +++ b/kernel/workqueue.c @@ -5285,12 +5285,6 @@ static void pwq_release_workfn(struct kthread_work *= work) mutex_unlock(&wq->mutex); } =20 - if (!is_percpu_pool(pool)) { - mutex_lock(&wq_pool_mutex); - put_unbound_pool(pool); - mutex_unlock(&wq_pool_mutex); - } - if (!list_empty(&pwq->pending_node)) { struct wq_node_nr_active *nna =3D wq_node_nr_active(pwq->wq, pwq->pool->node); @@ -5300,6 +5294,12 @@ static void pwq_release_workfn(struct kthread_work *= work) raw_spin_unlock_irq(&nna->lock); } =20 + if (!is_percpu_pool(pool)) { + mutex_lock(&wq_pool_mutex); + put_unbound_pool(pool); + mutex_unlock(&wq_pool_mutex); + } + kfree_rcu(pwq, rcu); =20 /* --=20 2.43.0