On Tue, Sep 29, 2026 at 10:20 AM Hao Ge <[email protected]> wrote: > > The reservation is already stored in the maple tree when > vm_module_tags_populate() fails. A failed load never unloads the > module, so nothing releases the entry. Release it and roll > module_tags.size back. Without the rollback a concurrent load that > already passed needs_section_mem() can reuse the freed gap, skip > vm_module_tags_populate() and write to unmapped memory. > > Fixes: 4835f747d3ed ("alloc_tag: support for page allocation tag compression") > Fixes: 0f9b685626da ("alloc_tag: populate memory for module tags as needed")
I think 0f9b685626da is the only one being fixed here. 4835f747d3ed contains the issue simply because 0f9b685626da already had it. > Reported-by: Sashiko <[email protected]> > Cc: [email protected] > Signed-off-by: Hao Ge <[email protected]> Acked-by: Suren Baghdasaryan <[email protected]> > --- > mm/alloc_tag.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/mm/alloc_tag.c b/mm/alloc_tag.c > index 2070e682fe10..3e6306ee0764 100644 > --- a/mm/alloc_tag.c > +++ b/mm/alloc_tag.c > @@ -947,6 +947,7 @@ static void *reserve_module_tags(struct module *mod, > unsigned long size, > return ret; > > if (module_tags.size < offset + size) { > + unsigned long prev_size = module_tags.size; > int grow_res; > > module_tags.size = offset + size; > @@ -961,6 +962,8 @@ static void *reserve_module_tags(struct module *mod, > unsigned long size, > shutdown_mem_profiling(true); > pr_err("Failed to allocate memory for allocation tags > in the module %s. Memory allocation profiling is disabled!\n", > mod->name); > + release_module_tags(mod, false); > + module_tags.size = prev_size; > return ERR_PTR(grow_res); > } > } > -- > 2.25.1 >

