From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f73.google.com (mail-wm1-f73.google.com [209.85.128.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 28B123C5DBA for ; Thu, 12 Mar 2026 13:14:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.73 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773321302; cv=none; b=salX/uSOBasQQHs2dbITB23C/ry58awQ654ZJKh6P0aO8hxGNSIBAepVfhXXxQalz0twaxSB3R7dHI53loZ5KV9N6zOHMaBCQACI/nzwMa201kP8NVmopVWzQdydOvw7YVdIqPuN7cYjM2XTsbH6b31zPTGcwyxTvEJXCWRXcyQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773321302; c=relaxed/simple; bh=grK+mtpv7AXhYDm+TZP/enoepTRNMghWNIsZ2+7k/a4=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=lJFrLOrEwXQtz3KJOplwoVeNofQNfgyKoxMwZ+VXLIFBXPxl6DUDtnYWJaqywxTE/kvOgbzO+9EUe29bvEa60mnE1XK6d6DpM3AHFoFW88EUXHX+PCjJuCidJlSZISDPYuc34kgo9m3i/P6uyUh+iP4Q1Q/5EsgUeiWDNePaAuo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--hmazur.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=kIYyRAin; arc=none smtp.client-ip=209.85.128.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--hmazur.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="kIYyRAin" Received: by mail-wm1-f73.google.com with SMTP id 5b1f17b1804b1-4837b6f6b93so7789135e9.3 for ; Thu, 12 Mar 2026 06:14:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1773321298; x=1773926098; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=dWSTF95QRNDxT+WTc7E7E1G9atdgc+PIwxyOxtBYOHY=; b=kIYyRAin4tH2zXEHIY+7/cl0UwajMxB5icqvthYWVsblitR7nZkfqzAqJL5o+qVGn2 RPyhENC+lN2bekHunKAxp45JaQ0LfgaOpCgmO00xt66ChjeysAomyTEvEmc3XUbEFNWk H8u9vM9tQ4q0bau2Uu3N7T42mAVwu07q6PvbdXQahmwlFM+bnHQXZvRwoCvLk4bkafrs XcuDI53Sy74zAy0+YGi0PSaREgbliCAeE5zOUxVUxYNjymHLpjcS9/7+XRpGRy3MK/uc UOZca0skZ5RgVB/Al6QV9nPQGkVZQU5ioheGJrrnye/F0EYrs8HMZ4vJfBsaKTAtsU55 W8+A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1773321298; x=1773926098; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=dWSTF95QRNDxT+WTc7E7E1G9atdgc+PIwxyOxtBYOHY=; b=J+LeqLDTYyp86LPYIYijtc6BiEs2+BdO7VUvuEtMWfHZpRkfA6F0Ar0hOjtcxyMnXx lwIec8E17DzyU9Je61m9Jst9qTxCHvQgei3PJLIYNXZcmKrlG670gDTWxqnQyLM+y1zL K2ydVyJVq8NDVgPWe5RZEMwEIkRV0LhWonAF+QOu95mwsDYQdR/nYbViIi2KGfMQ6pp9 OCoJpn2LrKZosAdHAMGRGneE0jXuNgaEYdqYxUQFK4shxEV8dIEJrXo1uzO6Vh1EyqKV MdMrbrnCr6q1s1VRxCDLm3MrXHt11WbOYiNX5sVacyndhP0tBqm6envsr5oUYK+o30g/ 6UnA== X-Forwarded-Encrypted: i=1; AJvYcCV8VwRV0KeRkG9C7UrUoeK0C1Os/KjBn5AaDza41UkWQ7xW1tHcw/wB8oazYf24PxMVGoMndTadG0nvP/Q=@vger.kernel.org X-Gm-Message-State: AOJu0YzulVr+cg4+BiFTEKPqIDKETqiKKJeq2jxKD48LZbhOz6zr2VYS pDnp8zVicOBXsJQMt6SV5LewSWlGkcSU1/CR2nUkizk1XJqqWUNhOgqZavHPQP3bLe6wSBOgV4R DVOBPSQ== X-Received: from wmqu11.prod.google.com ([2002:a05:600c:19cb:b0:483:71ce:bfb]) (user=hmazur job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:3511:b0:485:3473:d48b with SMTP id 5b1f17b1804b1-4854b139161mr108804515e9.35.1773321298259; Thu, 12 Mar 2026 06:14:58 -0700 (PDT) Date: Thu, 12 Mar 2026 13:14:37 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.53.0.473.g4a7958ca14-goog Message-ID: <20260312131438.361746-1-hmazur@google.com> Subject: [PATCH v1 0/1] Fix race condition in the memory management system From: Hubert Mazur To: Andrew Morton , Mike Rapoport Cc: Greg Kroah-Hartman , Stanislaw Kardach , Michal Krawczyk , Slawomir Rosek , Ryan Neph , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Hubert Mazur Content-Type: text/plain; charset="UTF-8" When 'ARCH_HAS_EXECMEM_ROX' is being enabled the memory management system will use caching techniques to optimize the allocations. The logic tries to find the appropriate memory block based on requested size. This can fail if current allocations is not sufficient hence kernel allocates a new block large enough in regards to the request. After the allocation is done, the new block is being added to the free_areas tree and then - traverses the tree with hope to find the matching piecie of memory. The operations of allocating new memory and traversing the tree are not protected by mutex and thus there is a chance that some other process will "steal" this shiny new block. It's a classic race condition for resources. Fix this accordingly by moving a new block of memory to busy fragments instead of free and return the pointer to memory. This simplifies the allocation logic since we don't firstly extend the free areas just to take it a bit later. In case the new memory allocation is required - do it and return to the caller. Hubert Mazur (1): mm: fix race condition in the memory management mm/execmem.c | 36 +++++++++++++++++------------------- 1 file changed, 17 insertions(+), 19 deletions(-) -- 2.53.0.851.ga537e3e6e9-goog