Re: [PATCH] mm/gup: fix NULL pointer dereference in fixup_user_fault()
From: Andrew Morton
Date: Sun Oct 04 2026 - 15:56:09 EST
On Sun, 4 Oct 2026 02:48:46 +0700 Nguyen Duy Nhat Anh <neganhat@xxxxxxxxx> wrote:
> In fixup_user_fault(), the 'unlocked' parameter is checked for NULL
> early on, allowing callers to pass NULL if they do not track whether the
> mmap lock was dropped.
>
> However, if handle_mm_fault() returns VM_FAULT_COMPLETED, line 1597
> dereferences 'unlocked' directly (*unlocked = true) without checking
> if it is NULL. Callers like s390's pci_mmio.c pass NULL for 'unlocked',
> leading to a kernel NULL pointer dereference when VM_FAULT_COMPLETED
> occurs.
>
> Fix this by checking if 'unlocked' is non-NULL before assigning to it.
This code is too subtle so you aren't the first to attempt to "fix" it.
The key hint is in the kerneldoc:
* @unlocked: did we unlock the mmap_lock while retrying, maybe NULL if caller
* does not allow retry. If NULL, the caller must guarantee
* that fault_flags does not contain FAULT_FLAG_ALLOW_RETRY.
Trace through the
FAULT_FLAG_ALLOW_RETRY/VM_FAULT_COMPLETED/VM_FAULT_RETRY logic
to confirm that the null deref is a cant-happen.
It would be great if you could pick through all this and propose
addition of a comment which will make this code less confusing for
others.
Thanks.