Files
Rafael Aquini 0a1805b580 zram: fix slot write race condition
JIRA: https://redhat.atlassian.net/browse/RHEL-145694
CVE: CVE-2025-39941

commit ce4be9e4307c5a60701ff6e0cafa74caffdc54ce
Author: Sergey Senozhatsky <senozhatsky@chromium.org>
Date:   Tue Sep 9 13:48:35 2025 +0900

    zram: fix slot write race condition

    Parallel concurrent writes to the same zram index result in leaked
    zsmalloc handles.  Schematically we can have something like this:

    CPU0                              CPU1
    zram_slot_lock()
    zs_free(handle)
    zram_slot_lock()
                                    zram_slot_lock()
                                    zs_free(handle)
                                    zram_slot_lock()

    compress                        compress
    handle = zs_malloc()            handle = zs_malloc()
    zram_slot_lock
    zram_set_handle(handle)
    zram_slot_lock
                                    zram_slot_lock
                                    zram_set_handle(handle)
                                    zram_slot_lock

    Either CPU0 or CPU1 zsmalloc handle will leak because zs_free() is done
    too early.  In fact, we need to reset zram entry right before we set its
    new handle, all under the same slot lock scope.

    Link: https://lkml.kernel.org/r/20250909045150.635345-1-senozhatsky@chromium.org
    Fixes: 71268035f5d7 ("zram: free slot memory early during write")
    Signed-off-by: Sergey Senozhatsky <senozhatsky@chromium.org>
    Reported-by: Changhui Zhong <czhong@redhat.com>
    Closes: https://lore.kernel.org/all/CAGVVp+UtpGoW5WEdEU7uVTtsSCjPN=ksN6EcvyypAtFDOUf30A@mail.gmail.com/
    Tested-by: Changhui Zhong <czhong@redhat.com>
    Cc: Jens Axboe <axboe@kernel.dk>
    Cc: Minchan Kim <minchan@kernel.org>
    Cc: <stable@vger.kernel.org>
    Signed-off-by: Andrew Morton <akpm@linux-foundation.org>

Signed-off-by: Rafael Aquini <raquini@redhat.com>
2026-07-01 16:18:57 -04:00
..
2026-07-01 16:18:57 -04:00
2026-02-28 19:32:36 +08:00