From nobody Fri Sep 25 20:02:11 2026 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 077C13148D0 for ; Wed, 9 Sep 2026 02:58:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788922715; cv=none; b=u+NoEbRq/qEm8Avfk43ktkrlrpcBkFoUqqlBgVVXuXWGrKaXnwXTqH9cXHaK6Inj50KGTmgFkpSLVxGG3ZGNiMurU+K0jO4DFY94PqMSrREGs1umJbuca+UHvwBzA3YSGM/BeyCTfazOW3/XWPvJ+IYppftV0FlQRCSVO4RYHVg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788922715; c=relaxed/simple; bh=K7uQcMj7z4luXqRDBQtVBqzLIiGA/6p1ooKeTvkbEwQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JLXhCoGszXB/320MgMSNQGl/XxgBXaZMFPiLLC8csI496JZ/28D6krdou/DcqbEyHPAkbnPpW8tlSosBtaWR6ufqxUcTGTSYXxLMGYdtQzTT6SX7h7isAHHTQ3twfGAWyFHP4wWWF3PdzmY65dtsB2WzKgbKIws/NRxLRolUItM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YWgCeAsz; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YWgCeAsz" Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-38dfe7eb825so4438794a91.0 for ; Tue, 08 Sep 2026 19:58:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788922713; x=1789527513; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sdv4IQZIJENY7PTBs1f5yW/iQydimvcyHFBLXl2Ap5U=; b=YWgCeAszWD58jLr8cMamtsH+7cPpBLTa4b3yW3RqNvZLwdRwF+HWW5hroYGTy0ngQQ 4jr5bB0OjCnxsw+taUOZOuoG8H8prvbIC5NJEvTrZY4B5Ze9SRYhDTunq809zvJz6XyU Q5CCOzV5DZuuE2edPLOrgBNbaYx1B3reIvvF6cyA5673Wg3uP39wGGBUd+1eXyUUwojO LQLXod0ZmEQfi8uYYmUb5sSO9FeOHach9nG7Wv+blF407x59KCGl+mBLadunxusFQTrS t6GEQk0LTAHQMZhBB3vg7/1YP5YqEU4tA9LC3ZgnKWm+BxHxlJy49bPBEPYjWvhmYj1v 5dhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788922713; x=1789527513; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=sdv4IQZIJENY7PTBs1f5yW/iQydimvcyHFBLXl2Ap5U=; b=Yv0Mdfrc/7Z4h4vlzukfG+KHFLd/K8YtQ4GaCuxss4ya9o5gB0Ijtx9Wa+OgdcZdDf 5BVKUpq1ips6LVr5F+heeEzcTTjJB8toKlI4OkrFNY2TC6eD7FnZ3sWZ8F1/MxKxuWv+ Xslb1jNCOq54P8KFaDTfyX5EbRPXe8Ch48bAGiDohsV6sgJKRhO6jqBqzNyVyeJudaH5 S236b+4/W0FIjJVbc+wNUbrIFLt+6eWb5ZBSWpj1nf1jzi5q9fazw6FiMcL2gH6epTuw S8XmBX0RlPdbauszYY4/x0fYbyWuIr+WeUFZpz49jFiywlZbFl0Yb4CWxJsyQIfTgYEA Reog== X-Forwarded-Encrypted: i=1; AKwUvByba1kbVdTsbIVEuUs6xWz8l6RDqqUgHC37YNj9Gi4rBf47tUdVZBJIijB+B3/dxkDSh8xEX+J8lgailao=@vger.kernel.org X-Gm-Message-State: AFuF++k+77VhCg2CGVmPVrFJhCLv7WkAZ5yhTp7hNQ26rBX7ogXZiA+P b10zeMt+bPFpb4iCKxoSn9QxdEPqpqb97Nm2ZWMka3eu4JMWhW2vDQfx X-Gm-Gg: AYBFou0Q5gz2KMtrWtUWEbdFuUzrOuOHm8jWC9VNyWsPubvInSsB9IcPLhKAjfTlOLN xsU927T19X0AXF0B+peqwWOhJZ9Q4QsCqoeRdsDyBAWiivIDTgYcRksRSipNRm70rcJMYtonSm9 JEAqH8REZM3H0ii3GnjuTTjQkT8g869iA80E8GK7cYg8j0kobZ82lUwEPVb9QKK/ZYSUerOGwMa L9RDrmG4dDFFVgs0T26MCKjLU/Mz2iPpCs7bUV9drqPnOAV+tgX3e4LX8AxYq5HSPa7Imq9oNO0 o6zxRV1w68GzYf/IM/1EE1xBIA6/IiKD4JUiZCR2+5hB+TfS7IVj4TaWsfT6eAeC2U1VpGUjEpP P7dmvNOfnYTgzZhQp9DQk5hJOM9NKStgt1F8E8/4qIuNZ/ixO6/AAoaD5jZT1XFI8PGvZfiqCQV Hz/Qh7VN8gaScjVxSxu05Ph15Dgs9lXanxLuRuK6qjRNhUCURyLL7xn/gCmUxjuP/otoKha2dpm jxRsM+U6eC2Cg== X-Received: by 2002:a17:90b:3a81:b0:398:c292:ac80 with SMTP id 98e67ed59e1d1-39b2612eaa4mr45424270a91.10.1788922713364; Tue, 08 Sep 2026 19:58:33 -0700 (PDT) Received: from localhost.localdomain ([240e:b8f:1df9:a600:c693:b19f:ada0:748]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39b08c39451sm35077172a91.7.2026.09.08.19.58.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 19:58:32 -0700 (PDT) From: Vernon Yang To: akpm@linux-foundation.org, david@kernel.org, ljs@kernel.org Cc: nico.pache@linux.dev, ryan.roberts@arm.com, dev.jain@arm.com, baohua@kernel.org, lance.yang@linux.dev, usama.arif@linux.dev, zokeefe@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, stable@vger.kernel.org, Vernon Yang Subject: [PATCH v5 1/3] mm: khugepaged: fix swap entry value to folio_pfn() Date: Wed, 9 Sep 2026 10:58:01 +0800 Message-ID: <20260909025804.3233645-2-vernon2gm@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260909025804.3233645-1-vernon2gm@gmail.com> References: <20260909025804.3233645-1-vernon2gm@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vernon Yang When the swap entries found exceed max_ptes_swap, the loop is left via break with folio still holding the xarray value that encodes the swap entry, not valid folio pointer. That value is passed to trace_mm_khugepaged_scan_file(), which feeds it to folio_pfn(). On FLATMEM and SPARSEMEM_VMEMMAP, the page_to_pfn() is plain pointer arithmetic, so the trace event merely prints bogus scan_pfn. On classic SPARSEMEM, the page_to_pfn() reads page->flags, dereferencing the tiny encoded integer and oopsing khugepaged whenever the trace event is enabled. So when folio is the swap entry value, simply set pfn to -1, just like exhausted scan naturally. And the folio_put() has maybe dropped the last reference of folio. The trace_mm_khugepaged_scan_file() is left with a dangling folio pointer. so using the folio_pfn() before dropping the reference, closing use-after-free window. Acked-by: David Hildenbrand (Arm) Fixes: d41fd2016ed0 ("mm/khugepaged: add tracepoint to hpage_collapse_scan_= file()") Cc: stable@vger.kernel.org Signed-off-by: Vernon Yang --- include/trace/events/huge_memory.h | 6 +++--- mm/khugepaged.c | 7 ++++++- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/include/trace/events/huge_memory.h b/include/trace/events/huge= _memory.h index 5a48c5406cce..7b526528f85b 100644 --- a/include/trace/events/huge_memory.h +++ b/include/trace/events/huge_memory.h @@ -178,10 +178,10 @@ TRACE_EVENT(mm_collapse_huge_page_swapin, =20 TRACE_EVENT(mm_khugepaged_scan_file, =20 - TP_PROTO(struct mm_struct *mm, struct folio *folio, struct file *file, + TP_PROTO(struct mm_struct *mm, unsigned long pfn, struct file *file, int present, int swap, int result), =20 - TP_ARGS(mm, folio, file, present, swap, result), + TP_ARGS(mm, pfn, file, present, swap, result), =20 TP_STRUCT__entry( __field(struct mm_struct *, mm) @@ -194,7 +194,7 @@ TRACE_EVENT(mm_khugepaged_scan_file, =20 TP_fast_assign( __entry->mm =3D mm; - __entry->pfn =3D folio ? folio_pfn(folio) : -1; + __entry->pfn =3D pfn; __assign_str(filename); __entry->present =3D present; __entry->swap =3D swap; diff --git a/mm/khugepaged.c b/mm/khugepaged.c index e6947fe142ee..6ee0ad13a31f 100644 --- a/mm/khugepaged.c +++ b/mm/khugepaged.c @@ -2690,6 +2690,7 @@ static enum scan_result collapse_scan_file(struct mm_= struct *mm, int present, swap; int node =3D NUMA_NO_NODE; enum scan_result result =3D SCAN_SUCCEED; + unsigned long failed_pfn =3D -1; =20 present =3D 0; swap =3D 0; @@ -2722,6 +2723,7 @@ static enum scan_result collapse_scan_file(struct mm_= struct *mm, =20 if (is_pmd_order(folio_order(folio))) { result =3D SCAN_PTE_MAPPED_HUGEPAGE; + failed_pfn =3D folio_pfn(folio); /* * PMD-sized THP implies that we can only try * retracting the PTE table. @@ -2733,6 +2735,7 @@ static enum scan_result collapse_scan_file(struct mm_= struct *mm, node =3D folio_nid(folio); if (collapse_scan_abort(node, cc)) { result =3D SCAN_SCAN_ABORT; + failed_pfn =3D folio_pfn(folio); folio_put(folio); break; } @@ -2740,12 +2743,14 @@ static enum scan_result collapse_scan_file(struct m= m_struct *mm, =20 if (!folio_test_lru(folio)) { result =3D SCAN_PAGE_LRU; + failed_pfn =3D folio_pfn(folio); folio_put(folio); break; } =20 if (folio_expected_ref_count(folio) + 1 !=3D folio_ref_count(folio)) { result =3D SCAN_PAGE_COUNT; + failed_pfn =3D folio_pfn(folio); folio_put(folio); break; } @@ -2780,7 +2785,7 @@ static enum scan_result collapse_scan_file(struct mm_= struct *mm, } } =20 - trace_mm_khugepaged_scan_file(mm, folio, file, present, swap, result); + trace_mm_khugepaged_scan_file(mm, failed_pfn, file, present, swap, result= ); return result; } =20 --=20 2.53.0 From nobody Fri Sep 25 20:02:11 2026 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 452432EEE8A for ; Wed, 9 Sep 2026 02:58:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788922721; cv=none; b=uY4JaG+Ulv55VV5b5/rd9pO9ujQ/sUTXtk9VCmbl+yzHHldvS5CH6i9E/NK4o6FjsXlqbIBkVV0RZiG/PiQe77K7GCb2hyYfVm76sqX7pAxmTZa1me7ZOAwey2qW6MYAuR1t5bEmaQ4cjhCM+kkLm1jFc/l7YFJkfU2YT/WZmH8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788922721; c=relaxed/simple; bh=LXlsTApBrqoiuYStPAwfG+fUQJZVGG67zHShaS1Y7Jo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jSs9UsKpTQtiCFaQyJeYvmuWfysFc/SRT8mOdvodsvtmZ2xqt3tiAHA+16aFVYXbGnjEdt68ykI8OPlIsYH+SyByQHrbeELHTmQL9da0SaSQcqEqfpRr2sEDCz1V8gftNHWKW0YGm1Od2lNGVnP7sNImebTK+Eg0Jf+HaC4aURE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=F31EtvlQ; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="F31EtvlQ" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-38e42560ebcso4007909a91.1 for ; Tue, 08 Sep 2026 19:58:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788922717; x=1789527517; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+CrA+cvlGJlbJCNYzltiXcEC/SgR4IipKiqObnP/BdA=; b=F31EtvlQdHqbNTjE2jPVwVCi56lpwAjxECZtcS/Oy/421ZU7FhvcuYy6c9IMx+sqno ZoKwCB2/lDSQXC/vw6UUgB5V9mYjrb7Uh3pQbrquwjx9tx9flNpKfmuSLQJCthGPeAh3 IBkgcFW0p8lNSKiTrCPHTNTqCb52+kqINKnsIxKsT3mlmGJv/EP56bNaSKoSvMn2pL/w mqO1HdmoxY4W2wL3ciR1vdaNBKHeQnPjNbX+GmVX2mindX7FdIv1W0tc5Ow9sT6xGK0t PE2NfP7wT/gUXE3cY9lkTeNlHQybzAgARxiD3FnHRxQzMljnd84n/9GfVzn+XsGv76rf DkBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788922717; x=1789527517; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+CrA+cvlGJlbJCNYzltiXcEC/SgR4IipKiqObnP/BdA=; b=Vaa3ZuzliWLzriV36Opgyj1PL4xCvUS4PsZs64zBXqmEkZ8LFuvIIgBgNwfRtDfbJ3 LhBdq9w2zRDFzq6h+JPK8JGqV5LvXkFGEJjwzp7YxwKmjq0WyckjzjmAKJYWiqc3V+Cr md+u4nhN9XYptcAL7A+v2BI4X88rs+ZtHDnoyFpMXbShLQNFFF/DtOBnUsiqf/zPKF/l 4lKJmflSKyvOqN02cPBbclT9fWpmyZp+GhRUX61d/erbLeSzB2GWnDLjOOBz+lkstkjh M/wIGBwUXUBM08MTX/osyTjUwM3wXaeKrUvZkkng5LcWENg/YQKFMkUR3XA316nKhxOX rEvg== X-Forwarded-Encrypted: i=1; AKwUvBxzfBFGeOH8hbhp5d4LcbzlRRjTAEx5NuAGn9GB0P/nvDgA3mL72v4RefpO+WFdbp/wYO54qaxkWtW81vg=@vger.kernel.org X-Gm-Message-State: AFuF++mZF8IhBrJdH4RZcj2oHGh9ldAb1iaULz/A0r8+52fUkepDGnUT KFAGxbgtOUom4ak36mXEm44hg+Eatmi9K8GbFywxeC5RGpub6U9o3847 X-Gm-Gg: AYBFou3yrnsV3ng8MENK0AdvzLgTQ2S3TpSoov19ywnESCMfZz8uZz17TiULfcaphZc DtYOU7uVdYgHSP6q6EJRT//DXJOjhw0cj6G9StW2n613N5XX8J/urcvLVGVQA3a4ADYMgvn0X5L xjxqfktWNOarxxtPO1hsLctOqJ6qdxrUl0br3httPOtZkQflLgpBF7V1xwNr27EzG16vpzVQaZ9 mEANfsiZGdwzDfxrW1YpHq3luQHw0HNDLWu5ukhfBAHymR5E3X/OnxR73a+7QD/K/rDiFMUPN7F 3evNwvKVibMsczEH0EBEu2Wf/RPZjxVefuoVN5uFD6/TWE2cydi/zef8KlD1z4jindN3iMCY2fj yAM8il2Y7n75aP39YwIBqkbdz0ttOk5MzSZcPDIKxmLf/5F2DgNMie0vu7zimR0HyOcqmFQ4Tmm Q6XyIP5PB6/ucN2Q/byc6r4H7PJvpXP3l19RWh/ylIVWyX3t1iRKf0qnqB3YKuv/Q+zVJL5vu8V kfhQWk83m4oDA== X-Received: by 2002:a17:90b:4d06:b0:366:10f1:3d91 with SMTP id 98e67ed59e1d1-39b2614df74mr46235543a91.1.1788922717300; Tue, 08 Sep 2026 19:58:37 -0700 (PDT) Received: from localhost.localdomain ([240e:b8f:1df9:a600:c693:b19f:ada0:748]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39b08c39451sm35077172a91.7.2026.09.08.19.58.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 19:58:36 -0700 (PDT) From: Vernon Yang To: akpm@linux-foundation.org, david@kernel.org, ljs@kernel.org Cc: nico.pache@linux.dev, ryan.roberts@arm.com, dev.jain@arm.com, baohua@kernel.org, lance.yang@linux.dev, usama.arif@linux.dev, zokeefe@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, stable@vger.kernel.org, Vernon Yang Subject: [PATCH v5 2/3] mm: khugepaged: fix folio is used after pte_unmap_unlock() Date: Wed, 9 Sep 2026 10:58:02 +0800 Message-ID: <20260909025804.3233645-3-vernon2gm@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260909025804.3233645-1-vernon2gm@gmail.com> References: <20260909025804.3233645-1-vernon2gm@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vernon Yang After the page table lock has dropped, the folio can be freed concurrently. The trace_mm_khugepaged_scan_pmd() is left with a dangling folio pointer. So using the folio_pfn() before dropping the page table lock, closing use-after-free window. And other pre-existing bug, When the `for (i =3D 0; i < HPAGE_PMD_NR; i++)` iteration to terminate and the folio operation preceding is normal, but pfn will be incorrect. so we really only trace the PFN if it really was problematic. Acked-by: David Hildenbrand (Arm) Acked-by: Lorenzo Stoakes (ARM) Fixes: 7d2eba0557c1 ("mm: add tracepoint for scanning pages") Cc: stable@vger.kernel.org Signed-off-by: Vernon Yang --- include/trace/events/huge_memory.h | 6 +++--- mm/khugepaged.c | 10 +++++++++- 2 files changed, 12 insertions(+), 4 deletions(-) diff --git a/include/trace/events/huge_memory.h b/include/trace/events/huge= _memory.h index 7b526528f85b..fa828967e1fb 100644 --- a/include/trace/events/huge_memory.h +++ b/include/trace/events/huge_memory.h @@ -55,10 +55,10 @@ SCAN_STATUS =20 TRACE_EVENT(mm_khugepaged_scan_pmd, =20 - TP_PROTO(struct mm_struct *mm, struct folio *folio, + TP_PROTO(struct mm_struct *mm, unsigned long pfn, int referenced, int none_or_zero, int status, int unmapped), =20 - TP_ARGS(mm, folio, referenced, none_or_zero, status, unmapped), + TP_ARGS(mm, pfn, referenced, none_or_zero, status, unmapped), =20 TP_STRUCT__entry( __field(struct mm_struct *, mm) @@ -71,7 +71,7 @@ TRACE_EVENT(mm_khugepaged_scan_pmd, =20 TP_fast_assign( __entry->mm =3D mm; - __entry->pfn =3D folio ? folio_pfn(folio) : -1; + __entry->pfn =3D pfn; __entry->referenced =3D referenced; __entry->none_or_zero =3D none_or_zero; __entry->status =3D status; diff --git a/mm/khugepaged.c b/mm/khugepaged.c index 6ee0ad13a31f..b352c1330f8e 100644 --- a/mm/khugepaged.c +++ b/mm/khugepaged.c @@ -1612,6 +1612,7 @@ static enum scan_result collapse_scan_pmd(struct mm_s= truct *mm, enum scan_result result =3D SCAN_FAIL; struct page *page =3D NULL; struct folio *folio =3D NULL; + unsigned long failed_pfn =3D -1; unsigned long addr; unsigned long enabled_orders; spinlock_t *ptl; @@ -1706,11 +1707,13 @@ static enum scan_result collapse_scan_pmd(struct mm= _struct *mm, if (cc->is_khugepaged && !(vma->vm_flags & VM_DROPPABLE) && folio_test_lazyfree(folio) && !pte_dirty(pteval)) { result =3D SCAN_PAGE_LAZYFREE; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 if (!folio_test_anon(folio)) { result =3D SCAN_PAGE_ANON; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 @@ -1721,6 +1724,7 @@ static enum scan_result collapse_scan_pmd(struct mm_s= truct *mm, if (folio_maybe_mapped_shared(folio)) { if (++shared > max_ptes_shared) { result =3D SCAN_EXCEED_SHARED_PTE; + failed_pfn =3D folio_pfn(folio); count_collapse_event(HPAGE_PMD_ORDER, THP_SCAN_EXCEED_SHARED_PTE, MTHP_STAT_COLLAPSE_EXCEED_SHARED); goto out_unmap; @@ -1738,15 +1742,18 @@ static enum scan_result collapse_scan_pmd(struct mm= _struct *mm, node =3D folio_nid(folio); if (collapse_scan_abort(node, cc)) { result =3D SCAN_SCAN_ABORT; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } cc->node_load[node]++; if (!folio_test_lru(folio)) { result =3D SCAN_PAGE_LRU; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } if (folio_test_locked(folio)) { result =3D SCAN_PAGE_LOCK; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 @@ -1759,6 +1766,7 @@ static enum scan_result collapse_scan_pmd(struct mm_s= truct *mm, */ if (folio_expected_ref_count(folio) !=3D folio_ref_count(folio)) { result =3D SCAN_PAGE_COUNT; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 @@ -1784,7 +1792,7 @@ static enum scan_result collapse_scan_pmd(struct mm_s= truct *mm, *lock_dropped =3D true; } out: - trace_mm_khugepaged_scan_pmd(mm, folio, referenced, + trace_mm_khugepaged_scan_pmd(mm, failed_pfn, referenced, none_or_zero, result, unmapped); return result; } --=20 2.53.0 From nobody Fri Sep 25 20:02:11 2026 Received: from mail-pj1-f45.google.com (mail-pj1-f45.google.com [209.85.216.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B47CF344D91 for ; Wed, 9 Sep 2026 02:58:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788922723; cv=none; b=dNsRIiz7NIFohOSnvPapgIjEskNhtUkd0sFPPep3sHH9XGOfZGihqaauv/dBHveuZX4c1Yy4cFDS+VDhvN/14hvoqIJ03LwxGDEqbbsE6peMQBV6P7O4lc/tNzme8UBR2E6lP4sjOKPwlRLnxmK7Y+bSN9g1wV3bIxgYSq5TzIo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788922723; c=relaxed/simple; bh=x7CnzgkXZPi5Hybsq0SY68kW0PZsH8p9kacRNmwuD3Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=peyR0RmfjtHHNP9eh/s6bzCb7n/BJ8sH/eyga4wMT2h2UPklW/sLQwnA8PeBmExEFk3dxOFuYciVoScUxkph/AZbP5TiDMfNgdbduhHlKGE0IWddVc9uKSJxaVQuW39ixuSo3xoPhADXc/6KyoW+bJzvVsSKx1RBP9AZRPFxDcE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=me7t9B76; arc=none smtp.client-ip=209.85.216.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="me7t9B76" Received: by mail-pj1-f45.google.com with SMTP id 98e67ed59e1d1-38ea87caafeso4528866a91.3 for ; Tue, 08 Sep 2026 19:58:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788922721; x=1789527521; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TXwn16IKsAcJzLpp2jrqz/yHYVFBEEgFTxz9PHTQzdM=; b=me7t9B76b9HvgUWueTRrWOpYn9vzxQgTmYtLIFkFtImwbUUqO1W4Tjv6qwg7D6X/WD 4h91BXeKz/M440ft/Jyf9XXHlhsY+vu0y85mLoBNl7aNiGapDtUFS77PmuafncekGpzp 6C/sUtR0xhLD9xo6Q4dtJhMQ5BSoqSwkMXRcTXdOGsEi3JnLbKrh3PvWR+vILwk/Bu29 EUAXpPCTxXk9Ux5Wyy0zeLGOBT5yvRjxL8dxlgg3bDDgPkfx3K9/R2BtDxMw0HAmtj3O 6EvIHrK+P2nVs2nDDkka+bByufvl7Z2MuDjdQ9SIaOu5luRNfU1AIWd069Kts4gUjupW NR6A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788922721; x=1789527521; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TXwn16IKsAcJzLpp2jrqz/yHYVFBEEgFTxz9PHTQzdM=; b=dCaeAqHNm46RIvimYKVAe7YHzovewhvZ9yDhhYXsvj3uMg7AHTxFjw6JzWahc2JhHo aqARYyo5gNEUZmp9YTiq13P8wwfX+TO0tstF1N2dDDemQF4ApiyYE2khFqt/j2EpJiZY XmTNCWjDiTctpXdLUabKBPu1bpl46g7s7FXoKl7i4DrT5KQ2xUpW7lZgb3ganZ+lTvoj grojcuQd8jWnR2I1E94lukP0Dhtvch680lHt3T9uDdDjs3vQDv6yge6vbXiko9w87NUG 26Bnz2G/3DXjhX46mfp8lAsMMJvLEaaivaFZ/m9kgtHTqcDdiYPu7L85LulaG4CUo+Y5 jm8A== X-Forwarded-Encrypted: i=1; AKwUvBzzmnM2782UAOQf5RKDVBKbvA2NFzD1/7Fr/+j0dVb6oHjEZCL3f2skxGAeY9Ki5ozCxCOAlFZwsNVKnjE=@vger.kernel.org X-Gm-Message-State: AFuF++lg0TSaQC0L0GtpqfOcDcbpbYkcKinwOkaOdvuE+qz3d39osGVk LVof6BuEJCZ8fqp3Ulqxv1hZ8mOHTepgeNavJXPr4frR13767D3pFc8j X-Gm-Gg: AYBFou11BN2jqQ7GeCdV5EJqAGXVYWaDQRaFVsdvNbiSjTYHJe/9eqhrMjVdhhnqtVL dqY5zCg0tJB/QUzjf8KMMQ3bVDheCkLS9JHvK4F4iB5Nfdv60V3OR7S+mPyZ3TYxhG0wHL4OGG+ TGz0R28xHfjzrbZyhSSoK2N4T7xinJQwFU/eSz2+yiSgN3FUwJwnDWynIR3z5QM6koB4UNciZF5 Xs/GacJmzbuL+Usi5XaLT7k3PzpFXPuUA1AAKcYkMun0HcXy8WzsdUX5OlwKIYwqsryZpfLegsu 6158MWrgg4axSK5L2qDi/TYwsq9pCQ6X/AGdjyaMpRQpGOWc8DuFx9m4Nvv73tl96PJSyYd6KRZ FO22I9X+mSXZhw/EcETaoeRA42Q3olPU7+RxUAeo6INFSItYFGGjN9WQvz8WxbZncE8Ty71bNZE pW2F1wQux2TpOC8qOXiP9EbH+1LkoFH185bit/gkyoMzW4LYzC6AG2PukPwYOdl3vHoX94KpQXF XSD2WMnM9vCww== X-Received: by 2002:a17:90b:4984:b0:381:25ce:bcc2 with SMTP id 98e67ed59e1d1-39b26104798mr44428583a91.6.1788922721071; Tue, 08 Sep 2026 19:58:41 -0700 (PDT) Received: from localhost.localdomain ([240e:b8f:1df9:a600:c693:b19f:ada0:748]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39b08c39451sm35077172a91.7.2026.09.08.19.58.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 19:58:40 -0700 (PDT) From: Vernon Yang To: akpm@linux-foundation.org, david@kernel.org, ljs@kernel.org Cc: nico.pache@linux.dev, ryan.roberts@arm.com, dev.jain@arm.com, baohua@kernel.org, lance.yang@linux.dev, usama.arif@linux.dev, zokeefe@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, stable@vger.kernel.org, Vernon Yang Subject: [PATCH v5 3/3] mm: khugepaged: fix folio is used after folio_put/unlock() Date: Wed, 9 Sep 2026 10:58:03 +0800 Message-ID: <20260909025804.3233645-4-vernon2gm@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260909025804.3233645-1-vernon2gm@gmail.com> References: <20260909025804.3233645-1-vernon2gm@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vernon Yang On the rollback path, folio_put() has already dropped the last reference of new_folio. On the success path, new_folio is already unlocked and can be freed concurrently. The trace_mm_khugepaged_collapse_file() is left with a dangling folio pointer. So using the folio_pfn() before dropping the reference, closing use-after-free window. Acked-by: David Hildenbrand (Arm) Acked-by: Lorenzo Stoakes (ARM) Fixes: 4c9473e87e75 ("mm/khugepaged: add tracepoint to collapse_file()") Cc: stable@vger.kernel.org Signed-off-by: Vernon Yang --- include/trace/events/huge_memory.h | 6 +++--- mm/khugepaged.c | 4 +++- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/include/trace/events/huge_memory.h b/include/trace/events/huge= _memory.h index fa828967e1fb..5fb4d92cfd84 100644 --- a/include/trace/events/huge_memory.h +++ b/include/trace/events/huge_memory.h @@ -211,10 +211,10 @@ TRACE_EVENT(mm_khugepaged_scan_file, ); =20 TRACE_EVENT(mm_khugepaged_collapse_file, - TP_PROTO(struct mm_struct *mm, struct folio *new_folio, pgoff_t index, + TP_PROTO(struct mm_struct *mm, unsigned long new_pfn, pgoff_t index, unsigned long addr, bool is_shmem, struct file *file, int nr, int result), - TP_ARGS(mm, new_folio, index, addr, is_shmem, file, nr, result), + TP_ARGS(mm, new_pfn, index, addr, is_shmem, file, nr, result), TP_STRUCT__entry( __field(struct mm_struct *, mm) __field(unsigned long, hpfn) @@ -228,7 +228,7 @@ TRACE_EVENT(mm_khugepaged_collapse_file, =20 TP_fast_assign( __entry->mm =3D mm; - __entry->hpfn =3D new_folio ? folio_pfn(new_folio) : -1; + __entry->hpfn =3D new_pfn; __entry->index =3D index; __entry->addr =3D addr; __entry->is_shmem =3D is_shmem; diff --git a/mm/khugepaged.c b/mm/khugepaged.c index b352c1330f8e..e13d233b9967 100644 --- a/mm/khugepaged.c +++ b/mm/khugepaged.c @@ -2260,6 +2260,7 @@ static enum scan_result collapse_file(struct mm_struc= t *mm, unsigned long addr, struct address_space *mapping =3D file->f_mapping; struct page *dst; struct folio *folio, *tmp, *new_folio; + unsigned long new_pfn =3D -1; pgoff_t index =3D 0, end =3D start + HPAGE_PMD_NR; LIST_HEAD(pagelist); XA_STATE_ORDER(xas, &mapping->i_pages, start, HPAGE_PMD_ORDER); @@ -2279,6 +2280,7 @@ static enum scan_result collapse_file(struct mm_struc= t *mm, unsigned long addr, result =3D alloc_charge_folio(&new_folio, mm, cc, HPAGE_PMD_ORDER); if (result !=3D SCAN_SUCCEED) goto out; + new_pfn =3D folio_pfn(new_folio); =20 mapping_set_update(&xas, mapping); =20 @@ -2682,7 +2684,7 @@ static enum scan_result collapse_file(struct mm_struc= t *mm, unsigned long addr, folio_put(new_folio); out: VM_BUG_ON(!list_empty(&pagelist)); - trace_mm_khugepaged_collapse_file(mm, new_folio, index, addr, is_shmem, f= ile, HPAGE_PMD_NR, result); + trace_mm_khugepaged_collapse_file(mm, new_pfn, index, addr, is_shmem, fil= e, HPAGE_PMD_NR, result); return result; } =20 --=20 2.53.0