Skip to content

Commit 2bdf777

Browse files
congwang-mkThomas Gleixner
authored andcommitted
sched/mm_cid: Prevent NULL mm dereference in sched_mm_cid_after_execve()
sched_mm_cid_after_execve() is called in bprm_execve()'s cleanup path even when exec_binprm() fails. For the init task's first execve(), this causes a problem: 1. current->mm is NULL (kernel threads don't have an mm) 2. sched_mm_cid_before_execve() exits early because mm is NULL 3. exec_binprm() fails (e.g., ENOENT for missing script interpreter) 4. sched_mm_cid_after_execve() is called with mm still NULL 5. sched_mm_cid_fork() is called unconditionally, triggering WARN_ON This is easily reproduced by booting with an init that is a shell script (#!/bin/sh) where the interpreter doesn't exist in the initramfs. Fix this by checking if t->mm is NULL before calling sched_mm_cid_fork(), matching the behavior of sched_mm_cid_before_execve() which already handles this case via sched_mm_cid_exit()'s early return. Fixes: b0c3d51 ("sched/mmcid: Provide precomputed maximal value") Signed-off-by: Cong Wang <cwang@multikernel.io> Signed-off-by: Thomas Gleixner <tglx@kernel.org> Reviewed-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com> Acked-by: Will Deacon <will@kernel.org> Link: https://patch.msgid.link/20251223215113.639686-1-xiyou.wangcong@gmail.com
1 parent 9ace475 commit 2bdf777

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

kernel/sched/core.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10694,10 +10694,11 @@ void sched_mm_cid_before_execve(struct task_struct *t)
1069410694
sched_mm_cid_exit(t);
1069510695
}
1069610696

10697-
/* Reactivate MM CID after successful execve() */
10697+
/* Reactivate MM CID after execve() */
1069810698
void sched_mm_cid_after_execve(struct task_struct *t)
1069910699
{
10700-
sched_mm_cid_fork(t);
10700+
if (t->mm)
10701+
sched_mm_cid_fork(t);
1070110702
}
1070210703

1070310704
static void mm_cid_work_fn(struct work_struct *work)

0 commit comments

Comments
 (0)