On Tue, Sep 29, 2026 at 10:20 AM Hao Ge <[email protected]> wrote:
>
> The reservation is already stored in the maple tree when
> vm_module_tags_populate() fails. A failed load never unloads the
> module, so nothing releases the entry. Release it and roll
> module_tags.size back. Without the rollback a concurrent load that
> already passed needs_section_mem() can reuse the freed gap, skip
> vm_module_tags_populate() and write to unmapped memory.
>
> Fixes: 4835f747d3ed ("alloc_tag: support for page allocation tag compression")
> Fixes: 0f9b685626da ("alloc_tag: populate memory for module tags as needed")

I think 0f9b685626da is the only one being fixed here. 4835f747d3ed
contains the issue simply because 0f9b685626da already had it.

> Reported-by: Sashiko <[email protected]>
> Cc: [email protected]
> Signed-off-by: Hao Ge <[email protected]>

Acked-by: Suren Baghdasaryan <[email protected]>

> ---
>  mm/alloc_tag.c | 3 +++
>  1 file changed, 3 insertions(+)
>
> diff --git a/mm/alloc_tag.c b/mm/alloc_tag.c
> index 2070e682fe10..3e6306ee0764 100644
> --- a/mm/alloc_tag.c
> +++ b/mm/alloc_tag.c
> @@ -947,6 +947,7 @@ static void *reserve_module_tags(struct module *mod, 
> unsigned long size,
>                 return ret;
>
>         if (module_tags.size < offset + size) {
> +               unsigned long prev_size = module_tags.size;
>                 int grow_res;
>
>                 module_tags.size = offset + size;
> @@ -961,6 +962,8 @@ static void *reserve_module_tags(struct module *mod, 
> unsigned long size,
>                         shutdown_mem_profiling(true);
>                         pr_err("Failed to allocate memory for allocation tags 
> in the module %s. Memory allocation profiling is disabled!\n",
>                                mod->name);
> +                       release_module_tags(mod, false);
> +                       module_tags.size = prev_size;
>                         return ERR_PTR(grow_res);
>                 }
>         }
> --
> 2.25.1
>

Reply via email to