From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f172.google.com (mail-oi1-f172.google.com [209.85.167.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AFBA536308F for ; Tue, 9 Jun 2026 18:25:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781029549; cv=none; b=TvmLLv/Uq+hjHbSQQliprRfY1kSRK0tU5gYbLkcB4uBI4IQ2qMYH7qjGbbACqILh+Q0HZlpnxO1ar491mjawAecd4dSiPWu57x4d5TguIIETtyzb0ooYcmZ5qC650wRUpq7BLDP28qP6LXijrZ7cGcVcFhMVHJ1g/1ed29iHKSQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781029549; c=relaxed/simple; bh=NbaRYw61bOR1p7MXHPpxV5tZ5SxZ7OVKFA9zuWc3bBI=; h=Mime-Version:Content-Type:Date:Message-Id:To:Cc:Subject:From: References:In-Reply-To; b=cPZKX0zWCT+eQ3A056CpNq6sMM0oNyyyHRZKeVjMJGeL1pdqJd9G+avBiQLPYC74DK8MW2HR9tYwHEtT4IHKdYVRwOkp1PjOS7iu7gcWLVqpA0dp0ZyGFegN9YVsmU3RwTWEapzXWNWtxzw9N59JCcNaZ/UDSUi6FInNYHZMnII= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=paKFfQJ7; arc=none smtp.client-ip=209.85.167.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="paKFfQJ7" Received: by mail-oi1-f172.google.com with SMTP id 5614622812f47-4863a7dac63so3050664b6e.1 for ; Tue, 09 Jun 2026 11:25:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781029547; x=1781634347; darn=vger.kernel.org; h=in-reply-to:references:from:subject:cc:to:message-id:date :content-transfer-encoding:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=oq36UDZ4+f+no94YaPKFhTgujqNZEmF0RCHQTwYwfLg=; b=paKFfQJ7l0Lt34ba/EksYnOILs9hi8o3WLAADFWe3mHrdA8M2+wiVbJ9UD9R1uY4FG 1JJY+vALZMI8yH7is3U+Vdfcvr4rPI2rjgbOk5z++TyolQwYk6uUu6XkFH5al9K7nYkJ UzzlEzSm6FvCo/w4ovmKCosDMR1Gfn98Nyt+HI9TwPMXCNs1js52wVkqCFWY6HMpU+ev jMJkda5FSPCCehGgmc8SupnHrf/j2eXQ3UCUGV3xXuqVL2/AmBYBX80AlTqBMDHN7a26 p8WacltV5OrQwckkuJfYp3T5fweJAM1xe4bvBaHUCT9IG/4thezqFq4mxhU/CPw26/2h KqoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781029547; x=1781634347; h=in-reply-to:references:from:subject:cc:to:message-id:date :content-transfer-encoding:mime-version:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=oq36UDZ4+f+no94YaPKFhTgujqNZEmF0RCHQTwYwfLg=; b=PljIVshUd/ITZKKUBwB8Ig4yZr29RfmUwqAnBZKLv5eFzKmKGxFf+xEJawDeZkXu0W IiNVusnUtN3ky33Cr9+XxwJ8DZyn1mLG4UlPfRPJTZJrFVzHwFeUv7BfMntchdj+6Cyc gk+3Mp32+mRC7sK8x/YDFsuNG9XER9MLxrKa4fKDFT4ZhAnO2gZBYLCSjmaKAFQ5STmX Hjd8vMgBWz+vYE7bVCSOET5aqsK2a01PT3vg2iFjpxn48wNTaSA9VSqnZVyNtcEdKT4U uWiUdmQC2CnqajeOEeA4+24OGPjKX3sfoAKu0mgFToMzgBI7H7ktf1vZlVoSQLacGM18 GA0w== X-Forwarded-Encrypted: i=1; AFNElJ/YU44n0LfvROJ6MpCbcWurgykls6/rh/fvmD8eQXU+5vey5u+2+G/s7gpgvh77Qip/Jhy+tNjq1xZxOF4=@vger.kernel.org X-Gm-Message-State: AOJu0YxfC9FjUXhH0FzP2JsDqelVUj2WFYrZR4CWo2ZVk+j74tMiSlhi C9SmLmgqE4zyJeZp8lEtwek6T67FvMTBLjgHIt/ycEji4RzuhJInMGwx X-Gm-Gg: Acq92OFa4ZqTWy5xpDP/OOm+eE0q/hOgIFwkjLdu5MPHHe0d54liKW7y3mbh96fKShN 7CUcooM9JXgcamKnjbuwWz5mLw29LS5J7NU3XWrzJSidgzdVomaKAuN9uQAQ/k33WdmOlHi/Az9 1J/phQfai9pfI1bTzubXJkyQXNhrCrLx9HvxYweH7GFOEP9XX/T23IgVWKN4zZIdJnp9GYFyVS9 TCRBopkUZq5MeAf06qjdtG4vytPbmW5331qPv+2DSskExGI8Jo8lKsuR/5AS+YFSMgIynn3Tdoh lPugBLFOadAtjt4PoxaGq4Z3puhmWW28qS+MCGgYtduw7jn6Wd7aYcjcia7oDdAq7mhGpLqu9Oi jjZhx2FSL1SjV22sFr34XxP9e/CnBF/msNMqDs2lDrGXjz2Ya/qqrz0RXrrOO1nTF98rtoS11qp Zne5P7QhX5KGzLrUpFxHdUerlYcFi08su4T8EhyiYiCfwq5sUfu9Tqp/R8o+3x7G2bH+qAB7/Bj Nms5lnDtR3INki22E5ogqE32Wja X-Received: by 2002:a05:6808:181c:b0:485:29ad:d1a8 with SMTP id 5614622812f47-4868deffc25mr12406135b6e.36.1781029546614; Tue, 09 Jun 2026 11:25:46 -0700 (PDT) Received: from localhost ([2a03:2880:10ff:46::]) by smtp.gmail.com with ESMTPSA id 5614622812f47-4865b32f372sm16380233b6e.0.2026.06.09.11.25.45 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 09 Jun 2026 11:25:46 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Tue, 09 Jun 2026 11:25:44 -0700 Message-Id: To: "Sanghyun Park" , , , , Cc: , , Subject: Re: [PATCH bpf v3] bpf: Fix use-after-free on mm_struct in bpf_find_vma() From: "Alexei Starovoitov" X-Mailer: aerc References: <20260609105216.3536839-1-sanghyun.park.cnu@gmail.com> In-Reply-To: <20260609105216.3536839-1-sanghyun.park.cnu@gmail.com> On Tue Jun 9, 2026 at 3:52 AM PDT, Sanghyun Park wrote: > bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without > holding a reference on the mm. On a foreign task, a concurrent exit_mm() > can free the mm_struct between the lockless read and the trylock, > resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU. > > For the current task, task->mm is stable. For a foreign task, pin the mm > under task->alloc_lock and release it with mmput_async(), mirroring commi= t > d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator"). > Use spin_trylock() instead of get_task_mm() so BPF context does not block > on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the > foreign-task path because dropping the mm reference is not safe there. > > Race: > > CPU0 (BPF program) CPU1 (exiting task) > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D > bpf_find_vma(foreign_task): > mm =3D task->mm > exit_mm(): > task->mm =3D NULL > mmput(mm) -> frees mm_struct > mmap_read_trylock(mm) > // UAF on mm > > Fixes: 7c7e3d31e785 ("bpf: Introduce helper bpf_find_vma") > Signed-off-by: Sanghyun Park > --- > v3: > - Drop get_task_mm()+mmput(); mirror d8e27d2d22b6 with alloc_lock > trylock + mmput_async(). (Yonghong Song) > - Reject irqs-disabled contexts on the foreign-task path. > - Reject foreign-task path when !CONFIG_MMU: bpf_iter_mmput_async() > falls back to mmput() which may sleep, and bpf_find_vma() can run > in non-sleepable context. > - Shorten the foreign-task rationale comment and trim the changelog body= . > - Fix the v2's whitespace damage. Pls use [PATCH bpf-next] subject. pw-bot: cr