Thread (82 messages) flat view 82 messages, 3 authors, 5d ago

Re: [PATCH v3 01/40] mm/vma: fix mmap_prepare file handling, remove file_doesnt_need_get

From: sashiko-bot@kernel.org
Date: 2026-09-17 16:54:08
Also in: bpf, dri-devel, kvm, kvmarm, linux-perf-users, linux-rdma, linux-s390, linux-scsi, selinux

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mm: NULL pointer dereference in compat_vma_mmap() error and success paths
--

commit ed2cb69a22a3cc12d20a6c5599880de22d11566c
Author: Lorenzo Stoakes (ARM) [off-list ref]

mm/vma: fix mmap_prepare file handling, remove file_doesnt_need_get
    
The map->file_doesnt_need_get flag is confusing and the existing
implementation has holes.

[ ... ]
quoted hunk ↗ jump to hunk
diff --git a/mm/util.c b/mm/util.c
index bf0513d1d3d08..016932780925e 100644
--- a/mm/util.c
+++ b/mm/util.c
@@ -1228,8 +1228,11 @@ int __compat_vma_mmap(struct vm_area_desc *desc,
 
 	/* Perform any preparatory tasks for mmap action. */
 	err = mmap_action_prepare(desc);
-	if (err)
+	if (err) {
+		if (desc->vm_file != vma->vm_file)
+			fput(desc->vm_file);
[Severity: High]
Is it possible for desc->vm_file to be NULL here? If a stacked driver's
mmap_prepare() hook changes the mapping to anonymous (clearing desc->vm_file
to NULL) and mmap_action_prepare() fails, this error path would call
fput(desc->vm_file) passing NULL. Because fput() does not tolerate NULL
pointers, would this lead to a NULL pointer dereference?
 		return err;
+	}
 	/* Update the VMA from the descriptor. */
 	compat_set_vma_from_desc(vma, desc);
 	/* Complete any specified mmap actions. */
[ ... ]
quoted hunk ↗ jump to hunk
diff --git a/mm/vma.h b/mm/vma.h
index e97bd2dfa786d..f15faa83f3d63 100644
--- a/mm/vma.h
+++ b/mm/vma.h
@@ -394,8 +394,10 @@ static inline void compat_set_vma_from_desc(struct vm_area_struct *vma,
 
 	/* Mutable fields. Populated with initial state. */
 	vma_set_pgoff(vma, desc->pgoff);
-	if (desc->vm_file != vma->vm_file)
-		vma_set_file(vma, desc->vm_file);
+	if (desc->vm_file != vma->vm_file) {
+		fput(vma->vm_file);
[Severity: High]
Similarly, could vma->vm_file be NULL here? If __compat_vma_mmap() is invoked
on an initially anonymous VMA (where vma->vm_file is NULL) and the driver
provides a backing file, this success path calls fput(vma->vm_file) passing
NULL.
+		vma->vm_file = desc->vm_file;
+	}
 	vma->flags = desc->vma_flags;
 	vma->vm_page_prot = desc->page_prot;
-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917-b4-mmap-prepare-vma-flag-sanify-v3-0-4583d8a23bca@kernel.org?part=1
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help