mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Bui Viet Dung <dungvn2345@gmail.com>
To: Tejun Heo <tj@kernel.org>, Lai Jiangshan <jiangshanlai@gmail.com>
Cc: Mike Snitzer <snitzer@hammerspace.com>,
	Trond Myklebust <trond.myklebust@hammerspace.com>,
	linux-kernel@vger.kernel.org,
	Bui Viet Dung <dungvn2345@gmail.com>,
	stable@vger.kernel.org
Subject: [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim()
Date: Thu,  8 Oct 2026 00:33:24 +0700	[thread overview]
Message-ID: <20261007173324.227988-1-dungvn2345@gmail.com> (raw)

current_wq_worker() indicates that %current is a kworker thread, but it
does not guarantee that the worker is currently executing a work item, as
worker->current_pwq is populated only while process_one_work() is actively
running the work function. Outside of that window (e.g. during worker idle,
initialization, or auxiliary execution paths), worker->current_pwq is NULL.

In current_is_workqueue_mem_reclaim(), worker->current_pwq->wq is
dereferenced without checking worker->current_pwq:

	return worker &&
		((worker->current_pwq->wq->flags &
		  (WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM);

If current_is_workqueue_mem_reclaim() is called when worker->current_pwq
is NULL, the kernel triggers a NULL pointer dereference.

This mirrors the issue recently fixed in is_chained_work() by commit
980db94e3eee ("workqueue: Fix NULL current_pwq deref in chained work check").

Guard the check with worker->current_pwq before dereferencing ->wq.

Fixes: da729ddd4a1b ("NFS/localio: issue IO inline when not in a memory-reclaim context")
Cc: stable@vger.kernel.org
Signed-off-by: Bui Viet Dung <dungvn2345@gmail.com>
---
 kernel/workqueue.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/workqueue.c b/kernel/workqueue.c
index c56c042d1c3..c1cb328bce3 100644
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -6320,7 +6320,7 @@ bool current_is_workqueue_mem_reclaim(void)
 {
 	struct worker *worker = current_wq_worker();
 
-	return worker &&
+	return worker && worker->current_pwq &&
 		((worker->current_pwq->wq->flags &
 		  (WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM);
 }
-- 
2.43.0


             reply	other threads:[~2026-10-07 17:33 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07 17:33 Bui Viet Dung [this message]
2026-10-07 18:08 ` Tejun Heo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007173324.227988-1-dungvn2345@gmail.com \
    --to=dungvn2345@gmail.com \
    --cc=jiangshanlai@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=snitzer@hammerspace.com \
    --cc=stable@vger.kernel.org \
    --cc=tj@kernel.org \
    --cc=trond.myklebust@hammerspace.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®