[PATCH v5 0/3] mm: khugepaged: fix tracepoint UAF
From: Vernon Yang <hidden>
Date: 2026-09-09 02:58:30
From: Vernon Yang <redacted> The khugepaged tracepoints take a folio pointer and call folio_pfn(), but by then the folio may no longer be valid: freed after folio_put(), folio_unlock() or pte_unmap_unlock(), or not a folio at all but an xarray-encoded swap entry. On classic SPARSEMEM, dereferencing it oopses khugepaged as soon as the trace event is enabled; on other memory models it merely prints a bogus pfn. Pass the pfn to the tracepoints directly, captured while the folio is still pinned, closing the use-after-free windows in mm_khugepaged_scan_file(), mm_khugepaged_scan_pmd() and mm_khugepaged_collapse_file(). This series is based on mm-new + revert v4. V4 -> V5: - Use a single trace statement. - Collect Acked-by. V3 -> V4: - Only trace the PFN if it really was problematic. - Calling the respective trace_xxx() functions separately on success and failure. - Set new_pfn once after successful alloc_charge_folio(). V2 -> V3: - Place folio_pfn() inside the xas_for_each() loop in PATCH#1. - Already defaulted the pfn value to -1, to simple it in PATCH#2. V1 -> V2: - Instead of passing the folio, just pass the pfn directly. - Using the folio_pfn() before dropping the reference or the page table lock. V4 : https://lore.kernel.org/linux-mm/20260828055926.346744-1-vernon2gm@gmail.com/ V3 : https://lore.kernel.org/linux-mm/20260824092935.73892-1-vernon2gm@gmail.com/ V2 : https://lore.kernel.org/linux-mm/20260815051924.194810-1-vernon2gm@gmail.com/ V1 : https://lore.kernel.org/linux-mm/20260811133655.267739-1-vernon2gm@gmail.com/ Vernon Yang (3): mm: khugepaged: fix swap entry value to folio_pfn() mm: khugepaged: fix folio is used after pte_unmap_unlock() mm: khugepaged: fix folio is used after folio_put/unlock() include/trace/events/huge_memory.h | 18 +++++++++--------- mm/khugepaged.c | 21 ++++++++++++++++++--- 2 files changed, 27 insertions(+), 12 deletions(-) -- 2.53.0