* [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim()
@ 2026-10-07 17:33 Bui Viet Dung
2026-10-07 18:08 ` Tejun Heo
0 siblings, 1 reply; 2+ messages in thread
From: Bui Viet Dung @ 2026-10-07 17:33 UTC (permalink / raw)
To: Tejun Heo, Lai Jiangshan
Cc: Mike Snitzer, Trond Myklebust, linux-kernel, Bui Viet Dung, stable
current_wq_worker() indicates that %current is a kworker thread, but it
does not guarantee that the worker is currently executing a work item, as
worker->current_pwq is populated only while process_one_work() is actively
running the work function. Outside of that window (e.g. during worker idle,
initialization, or auxiliary execution paths), worker->current_pwq is NULL.
In current_is_workqueue_mem_reclaim(), worker->current_pwq->wq is
dereferenced without checking worker->current_pwq:
return worker &&
((worker->current_pwq->wq->flags &
(WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM);
If current_is_workqueue_mem_reclaim() is called when worker->current_pwq
is NULL, the kernel triggers a NULL pointer dereference.
This mirrors the issue recently fixed in is_chained_work() by commit
980db94e3eee ("workqueue: Fix NULL current_pwq deref in chained work check").
Guard the check with worker->current_pwq before dereferencing ->wq.
Fixes: da729ddd4a1b ("NFS/localio: issue IO inline when not in a memory-reclaim context")
Cc: stable@vger.kernel.org
Signed-off-by: Bui Viet Dung <dungvn2345@gmail.com>
---
kernel/workqueue.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/workqueue.c b/kernel/workqueue.c
index c56c042d1c3..c1cb328bce3 100644
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -6320,7 +6320,7 @@ bool current_is_workqueue_mem_reclaim(void)
{
struct worker *worker = current_wq_worker();
- return worker &&
+ return worker && worker->current_pwq &&
((worker->current_pwq->wq->flags &
(WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM);
}
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim()
2026-10-07 17:33 [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim() Bui Viet Dung
@ 2026-10-07 18:08 ` Tejun Heo
0 siblings, 0 replies; 2+ messages in thread
From: Tejun Heo @ 2026-10-07 18:08 UTC (permalink / raw)
To: Bui Viet Dung
Cc: Lai Jiangshan, Mike Snitzer, Trond Myklebust, linux-kernel, stable
Hello, Dung.
The same fix was posted earlier by Pavankumar Kondeti and is now applied to
wq/for-7.3-fixes:
https://lore.kernel.org/all/20260928-wq_mem_reclaim_fix-v1-1-0dd37125cf47@oss.qualcomm.com/
Thanks.
--
tejun
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-07 18:08 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 17:33 [PATCH] workqueue: Fix NULL current_pwq deref in current_is_workqueue_mem_reclaim() Bui Viet Dung
2026-10-07 18:08 ` Tejun Heo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®