Re: [bugfix] try_to_unmap_cluster() passes out-of-bounds pte topte_unmap()

From: Andrew Morton
Date: Sun May 22 2005 - 17:02:20 EST


William Lee Irwin III <wli@xxxxxxxxxxxxxx> wrote:
>
> try_to_unmap_cluster() does:
> for (pte = pte_offset_map(pmd, address);
> address < end; pte++, address += PAGE_SIZE) {
> ...
> }
>
> pte_unmap(pte);
>
> It may take a little staring to notice, but pte can actually fall off
> the end of the pte page in this iteration,

That's about the third place we've had this bug. Whoever keeps adding it
really should stop.

Thanks.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/