From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2219C31F9A6 for ; Fri, 13 Mar 2026 12:42:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773405756; cv=none; b=gopPtn1qzmqL96bvgYs/u6CZ1KYM06Plv6Tnvyyhjc9VHhS0lemXMZg9cj4kh3+nauVgdUKOoTPAbZ7TmN3VCquTCkMVWp/atat2sgEGS5lk+yJtgXRq4rO4YeyQj4+6Lhq6WnMocfUVExAdKiCq2pNhCkAHrRc/L4i+gunE1iM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773405756; c=relaxed/simple; bh=e+78QdzSMZ47+MTYXgyWj/A2eUGRBxE9eKO3jfAUeqM=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=UHdT4BTfLjAb6TjAnfwn3C+6K72twjyUdNqnPMrswNP40ijun4No67WaJP9TszkygAiRe5jhkpMQ+f8udQ/XemuW+vLJ4aoRVgIocdftH3OetaW4ad6EFnxGSrnC3JGV+1Y44s496d+dl8DIEJawd9a00hEcl3V78U41hKtqweM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Y2IeYFuY; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Y2IeYFuY" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-358ed696623so976820a91.0 for ; Fri, 13 Mar 2026 05:42:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1773405754; x=1774010554; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=7Smofhd1+Cx7PBP4/YkqygOP/kFHVbHtSo6XIak7MVU=; b=Y2IeYFuY4b9Mz7uSlGMHc7hZ+hVB2VYGsWZIqLdNGjous92zxwwBBjBwMtJLMSuxYI V3TNVin2r8u51Jig+/f7jhW+7vLJ2GZSt0CcCpjDaDtSV3O+HgMZuwSD+A9sBkF5CoKX bbw5tgCZjy0o0rKKl6BSnKClOGnmrd/EfrBqSM983oyrs7x2TVabLfOOxFBdw2obTvJ0 gZzzydSZt5Zkm+0Fr+XE1xab4qcDfcb/CZy7dmrxsQedogVeN6PqjD5NDFaDs2pc1MEA xQGKtCPESrJWJdSUWFf3G++sI6nFhd7w0GLVsbKVdP7xU69xX6gc/EhGe32VijYsijrp hXrg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1773405754; x=1774010554; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=7Smofhd1+Cx7PBP4/YkqygOP/kFHVbHtSo6XIak7MVU=; b=j5wS4NF2somXlG9BeknVhY4b9rp9ubbPvRNbiebPSCS0IeH5VP/2vV2qUd8oNsWQyI tox3ter9khx1aKdF2fD2u3265hvonqLANvPQWeibsElGG3Plw2W85vqaCDENRbRhLGKX T8KxCm4zSrLN6F8CkC9TB0y1F5Jo6TG2pLjkxwY0B9Jp4lO7IHiOE1eIMKdE0TR5vmZK 4lw5VNOLEQcVJ2m3mfNapuq5zURqAlEyBXL6/4WRRRchzYUNvDJLdGETBD9k2cFu/EoL 6l07izl7GoY3uLae6m6Uq61grkTszwakatSxyKKhX3UXtjxuf1+VCoOvg1da8C9FOkj4 b6Og== X-Forwarded-Encrypted: i=1; AJvYcCUlgseW768sHcvqG8xRKDtjRZJ+fg+OtYWp0V22v4tF1dAvWhxh/xO9jfz/hrGTyrcFa4qjwUTUZGDeP5c=@vger.kernel.org X-Gm-Message-State: AOJu0Yx1EK4Z26UoVfWTF0vZpAzcayVPp28F2+KAMcbzTgjOpQrcremM qU6C11wCF+DGKePwtpCfl1owxcI6dROc0tUAmw9Mqwu6dysuiQ+YCrbt X-Gm-Gg: ATEYQzzdcXhwNO5ocZAyx2klAzGgTprQEvNl0ZhraVYmKkPTl/fpnSiYEs9dmqFi1aO n2H9wuT87fkQjFNGzGpjmbRpgBRuWiyB+5zJ+YcoqDbsmKOoj17uCBOV/oOUI8eJh0HuklMV9Lf znr38iY9JonTHeim6Stz2JKJP718UGVajzYKoeTEMXOntmqlDros4aXhKinPBJxGX8SuxxmBwDN ekIrulTEgqYTwmmH2qu2ouPmTQ2TyjtzanuxAdn9AEsCTiYhp+nmIOUbP355v8MZRzUMv1IeCNa 1XXOu4vjBAiN7aZBFD7jHrJtr+vlPRecDqfbh3Vb7N8VIl8rHYymBEN3GnqSMOxO6g5W9nTGOk8 JVQxoG7TmP3tQjAb3f6DZMH7waRui0zkAJiMVdsI6ORHD6eHZRjL2syuJQkBxayX/Giv6tKM6y7 V3UnXTL/vBkV5y2wk6R6mwtB6uBEhaXeAvFR/HBSmc57wgU6iwEdxfIIBzPw+Ds6RFSjO1RAjXU n59SQLzOGvs X-Received: by 2002:a17:90b:2d8a:b0:359:8d38:cdee with SMTP id 98e67ed59e1d1-35a21e39511mr3026090a91.2.1773405754451; Fri, 13 Mar 2026 05:42:34 -0700 (PDT) Received: from naup-virtual-machine (114-36-226-49.dynamic-ip.hinet.net. [114.36.226.49]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-35a2443181dsm1142741a91.5.2026.03.13.05.42.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 13 Mar 2026 05:42:34 -0700 (PDT) Date: Fri, 13 Mar 2026 20:42:31 +0800 From: Hao-Yu Yang To: Eric Dumazet Cc: security@kernel.org, tglx@kernel.org, mingo@redhat.com, linux-kernel@vger.kernel.org Subject: Re: [PATCH v1] futex: Use-after-free between futex_key_to_node_opt and vma_replace_policy Message-ID: References: <20260313120529.46754-1-naup96721@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: On Fri, Mar 13, 2026 at 01:26:21PM +0100, Eric Dumazet wrote: > On Fri, Mar 13, 2026 at 1:08 PM Hao-Yu Yang wrote: > > > > During futex_key_to_node_opt() execution, vma->vm_policy is read under > > speculative mmap lock and RCU. Concurrently, mbind() may call > > vma_replace_policy() which frees the old mempolicy immediately via > > kmem_cache_free(). > > > > This creates a race where __futex_key_to_node() dereferences a freed > > mempolicy pointer, causing a use-after-free read of mpol->mode. > > > > patch just initial attempt to patch and need more discussion. > > I think we need to remove this path or add some lock. > > > > Fixes: c042c505210d ("futex: Implement FUTEX2_MPOL") > > Reported-by: Hao-Yu Yang > > Signed-off-by: Hao-Yu Yang > > --- > > kernel/futex/core.c | 23 ----------------------- > > 1 file changed, 23 deletions(-) > > Good catch ! > > Adding rcu to __mpol_put() is really a no brainer. > > Thanks. > > diff --git a/include/linux/mempolicy.h b/include/linux/mempolicy.h > index 0fe96f3ab3ef02e902e1676e750c2006ecd6147f..65c732d440d2f4e4566204429f1e5e7487ab8f91 > 100644 > --- a/include/linux/mempolicy.h > +++ b/include/linux/mempolicy.h > @@ -55,6 +55,7 @@ struct mempolicy { > nodemask_t cpuset_mems_allowed; /* relative to these nodes */ > nodemask_t user_nodemask; /* nodemask passed by user */ > } w; > + struct rcu_head rcu; > }; > > /* > diff --git a/mm/mempolicy.c b/mm/mempolicy.c > index 0e5175f1c767d81394276559b9610c24d854f5bc..6dc61a3d4a32f74a06bf005acfd82d4a43112348 > 100644 > --- a/mm/mempolicy.c > +++ b/mm/mempolicy.c > @@ -487,7 +487,7 @@ void __mpol_put(struct mempolicy *pol) > { > if (!atomic_dec_and_test(&pol->refcnt)) > return; > - kmem_cache_free(policy_cache, pol); > + kfree_rcu(pol, rcu); > } > EXPORT_SYMBOL_FOR_MODULES(__mpol_put, "kvm"); Thanks for your review. I have send patch2. If this patch is good. I will cc to stable@vger.kernel.org