Re: [PATCH v2 0/2] ntfs: fix two kmap_local bugs on 32-bit kernels
From: Namjae Jeon
Date: Tue Oct 06 2026 - 09:30:01 EST
On Tue, Oct 6, 2026 at 1:53 PM Karl Mehltretter <kmehltretter@xxxxxxxxx> wrote:
>
> Two kmap_local bugs in the mount path of fs/ntfs. Both only show on
> 32-bit kernels with HIGHMEM, where kmap_local_folio() hands out fixmap
> slots from a per task stack of 16 entries. multi_v7_defconfig enables
> both NTFS_FS and HIGHMEM, so the stock 32-bit ARM configuration is
> affected.
>
> Patch 1: check_mft_mirror() unmaps pointers that were advanced past the
> end of the page. On 32-bit ARM this clears the wrong fixmap entry and
> the mount dies with a BUG a few calls later. syzkaller found it on a
> multi_v7_defconfig kernel. A fresh mkntfs volume reproduces it on the
> first mount.
>
> Patch 2: ntfs_check_logfile() maps the same page once per loop
> iteration and unmaps it once, so a mount leaves three entries on the
> stack of the mounting task. After one mount the CPU it ran on can no
> longer be taken offline. A process that mounts ntfs volumes five times
> hits the BUG_ON() in kmap_local_idx_push(). x86-32 also warns when
> mount(2) returns.
>
> The two fixes are independent of each other. Patch 2 was tested on top
> of patch 1. Both were tested on 32-bit ARM and x86-32 in QEMU. Details
> are below the --- line of each patch.
>
> Changes in v2:
> - v1 carried an older copy of patch 2 as a second 2/2 by mistake. The
> patches are unchanged.
>
> v1:
> https://lore.kernel.org/r/20261006043810.5393-1-kmehltretter@xxxxxxxxx/
>
> Karl Mehltretter (2):
> ntfs: fix kunmap_local() of advanced pointers in check_mft_mirror()
> ntfs: fix kmap_local leak in ntfs_check_logfile()
Applied them to #ntfs-next.
Thanks!