mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim()
@ 2026-10-07 17:33 Bui Viet Dung
  2026-10-07 18:08 ` Tejun Heo
  0 siblings, 1 reply; 2+ messages in thread
From: Bui Viet Dung @ 2026-10-07 17:33 UTC (permalink / raw)
  To: Tejun Heo, Lai Jiangshan
  Cc: Mike Snitzer, Trond Myklebust, linux-kernel, Bui Viet Dung, stable

current_wq_worker() indicates that %current is a kworker thread, but it
does not guarantee that the worker is currently executing a work item, as
worker->current_pwq is populated only while process_one_work() is actively
running the work function. Outside of that window (e.g. during worker idle,
initialization, or auxiliary execution paths), worker->current_pwq is NULL.

In current_is_workqueue_mem_reclaim(), worker->current_pwq->wq is
dereferenced without checking worker->current_pwq:

	return worker &&
		((worker->current_pwq->wq->flags &
		  (WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM);

If current_is_workqueue_mem_reclaim() is called when worker->current_pwq
is NULL, the kernel triggers a NULL pointer dereference.

This mirrors the issue recently fixed in is_chained_work() by commit
980db94e3eee ("workqueue: Fix NULL current_pwq deref in chained work check").

Guard the check with worker->current_pwq before dereferencing ->wq.

Fixes: da729ddd4a1b ("NFS/localio: issue IO inline when not in a memory-reclaim context")
Cc: stable@vger.kernel.org
Signed-off-by: Bui Viet Dung <dungvn2345@gmail.com>
---
 kernel/workqueue.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/workqueue.c b/kernel/workqueue.c
index c56c042d1c3..c1cb328bce3 100644
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -6320,7 +6320,7 @@ bool current_is_workqueue_mem_reclaim(void)
 {
 	struct worker *worker = current_wq_worker();
 
-	return worker &&
+	return worker && worker->current_pwq &&
 		((worker->current_pwq->wq->flags &
 		  (WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM);
 }
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim()
  2026-10-07 17:33 [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim() Bui Viet Dung
@ 2026-10-07 18:08 ` Tejun Heo
  0 siblings, 0 replies; 2+ messages in thread
From: Tejun Heo @ 2026-10-07 18:08 UTC (permalink / raw)
  To: Bui Viet Dung
  Cc: Lai Jiangshan, Mike Snitzer, Trond Myklebust, linux-kernel, stable

Hello, Dung.

The same fix was posted earlier by Pavankumar Kondeti and is now applied to
wq/for-7.3-fixes:

  https://lore.kernel.org/all/20260928-wq_mem_reclaim_fix-v1-1-0dd37125cf47@oss.qualcomm.com/

Thanks.

--
tejun

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-07 18:08 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 17:33 [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim() Bui Viet Dung
2026-10-07 18:08 ` Tejun Heo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®