Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
syzbot has triggered a NULL ptr dereference when allocation fault injection enforces a failure and alloc_mem_cgroup_per_node_info initializes memcg->nodeinfo only half way through. But __mem_cgroup_free still tries to free all per-node data and dereferences pn->lruvec_stat_cpu unconditioanlly even if the specific per-node data hasn't been initialized. The bug is quite unlikely to hit because small allocations do not fail and we would need quite some numa nodes to make struct mem_cgroup_per_node large enough to cross the costly order. Link: http://lkml.kernel.org/r/[email protected] Reported-by: [email protected] Fixes: 00f3ca2 ("mm: memcontrol: per-lruvec stats infrastructure") Signed-off-by: Michal Hocko <[email protected]> Reviewed-by: Andrey Ryabinin <[email protected]> Cc: Johannes Weiner <[email protected]> Signed-off-by: Andrew Morton <[email protected]> Signed-off-by: Linus Torvalds <[email protected]>
- Loading branch information