Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] mm: discontig_kernel_map_page_range() design causes stack UAF
--

commit 799ff7230f10cd5417cb7a7e859eaf5d9ab5e253
Author: Lorenzo Stoakes (ARM) <[email protected]>

mm: add mmap action for discontiguous kernel page mapping

This commit introduces a new mmap action for mapping discontiguous kernel
pages. It provides the discontig_kernel_page_ops interface, allowing
drivers to specify how batches of pages should be retrieved and mapped.

> diff --git a/include/linux/mm.h b/include/linux/mm.h
> index a1f2d375cf7d8..2a92193ac6a5e 100644
> --- a/include/linux/mm.h
> +++ b/include/linux/mm.h
[ ... ]
> +static inline void
> +discontig_kernel_map_page_range(struct discontig_kernel_page_state *state,
> +                             struct page **page_arr, unsigned long nr_pages)
> +{
> +     state->action = DISCONTIG_KERNEL_PAGE_MAP_PAGE_RANGE;
> +     state->__page_arr = page_arr;

[Severity: High]
Does this design create a risk of a stack use-after-free regression for
drivers using this helper?

Here, discontig_kernel_map_page_range() saves the page_arr pointer into the
state structure. However, this pointer is not consumed immediately.

> +     state->__nr_pages = nr_pages;
> +}

[ ... ]

> diff --git a/mm/memory.c b/mm/memory.c
> index 448342883e9da..45b21bb04a18b 100644
> --- a/mm/memory.c
> +++ b/mm/memory.c
[ ... ]
> +int map_discontig_kernel_pages_complete(struct vm_area_struct *vma,
> +                                     struct mmap_action *action)
> +{
[ ... ]
> +     do {
> +             unsigned long end, pgoff_end;
> +             unsigned long nr_pages;
> +
> +             /* Default to abort. */
> +             state.action = DISCONTIG_KERNEL_PAGE_ABORT;
> +             err = ops->get(&state);
> +             if (err || state.action == DISCONTIG_KERNEL_PAGE_ABORT)
> +                     return err;
> +             nr_pages = state.__nr_pages;
> +
> +             if (!nr_pages || nr_pages > state.nr_pages_remain)
> +                     return -EINVAL;
> +             end = state.addr + PAGE_SIZE * nr_pages;
> +             pgoff_end = state.pgoff + nr_pages;
> +
> +             err = apply_discontig_action(vma, &state);

[Severity: High]
Can this result in apply_discontig_action() dereferencing an invalid pointer?

Because discontiguous pages must be assembled into an array, and there is no
post-get callback to cleanly free dynamically allocated memory, drivers are
highly incentivized to allocate the page array on the stack inside their
ops->get() callback.

When ops->get() returns, its stack frame is popped. If page_arr points to
that destroyed stack frame, apply_discontig_action() will then read from it
via state->__page_arr when mapping the range, leading to a stack
use-after-free.

> +             if (err)
> +                     return err;
> +
> +             state.addr = end;
> +             state.pgoff = pgoff_end;
> +             state.nr_pages_mapped += nr_pages;
> +             state.nr_pages_remain -= nr_pages;
> +     } while (state.addr < vma->vm_end);
> +
> +     return 0;
> +}

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/20260917-b4-mmap-prepare-vma-flag-sanify-v3-0-4583d8a23...@kernel.org?part=8

Reply via email to