Re: [PATCH bpf-next v7] bpf: Fix use-after-free on mm_struct in bpf_find_vma()
From: patchwork-bot+netdevbpf
Date: Thu Jul 09 2026 - 02:10:36 EST
Hello:
This patch was applied to bpf/bpf-next.git (master)
by Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>:
On Wed, 8 Jul 2026 16:21:04 +0900 you wrote:
> bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without
> holding a reference on the mm. On a foreign task, a concurrent exit_mm()
> can free the mm_struct between the lockless read and the trylock,
> resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU.
>
> For the current task, task->mm is stable. For a foreign task, pin the mm
> under task->alloc_lock and release it with mmput_async(), mirroring commit
> d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator").
> Use spin_trylock() instead of get_task_mm() so BPF context does not block
> on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the
> foreign-task path because dropping the mm reference is not safe there.
>
> [...]
Here is the summary with links:
- [bpf-next,v7] bpf: Fix use-after-free on mm_struct in bpf_find_vma()
https://git.kernel.org/bpf/bpf-next/c/47b079e2117a
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html