{
    "version": 1,
    "title": "kernel BUG in validate_mm",
    "display-title": "kernel BUG in validate_mm (2)",
    "id": "49b6f675bead6969f913a3f7dcef4d28fdd13296",
    "status": "fixed",
    "fix-commits": [
        {
            "title": "mm: validate the mm before dropping the mmap lock",
            "link": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ae80b404198434e49e903dc3b1ba83e2c7bb3ee2",
            "hash": "ae80b404198434e49e903dc3b1ba83e2c7bb3ee2",
            "repo": "git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git",
            "branch": "master"
        }
    ],
    "cause-commit": {
        "title": "Linux 6.4",
        "link": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6995e2de6891c724bfeb2db33d7b87775f913ad1",
        "hash": "6995e2de6891c724bfeb2db33d7b87775f913ad1",
        "repo": "git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git",
        "branch": "master"
    },
    "discussions": [
        "https://lore.kernel.org/all/000000000000b35ea205ffc35fe1@google.com/T/",
        "https://lore.kernel.org/all/000000000000c3f89306002158b3@google.com/T/"
    ],
    "crashes": [
        {
            "title": "kernel BUG in validate_mm",
            "syz-reproducer": "/text?tag=ReproSyz&x=1511d490a80000",
            "c-reproducer": "/text?tag=ReproC&x=130e5cfb280000",
            "kernel-config": "/text?tag=KernelConfig&x=f5e1158c5b2f83bb",
            "kernel-source-git": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/?id=a901a3568fd26ca9c4a82d8bc5ed5b3ed844d451",
            "kernel-source-commit": "a901a3568fd26ca9c4a82d8bc5ed5b3ed844d451",
            "syzkaller-git": "https://github.com/google/syzkaller/commits/6e553898b1a72d31248a221bb0bff5bc62fce879",
            "syzkaller-commit": "6e553898b1a72d31248a221bb0bff5bc62fce879",
            "compiler-description": "gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2",
            "architecture": "amd64",
            "crash-report-link": "/text?tag=CrashReport&x=146aa484a80000"
        }
    ],
    "patch_modified_functions": [
        [
            "do_vmi_align_munmap",
            "mm/mmap.c"
        ]
    ],
    "cause_modified_functions": [],
    "patch_commit_date": "2023-07-03T17:08:50+00:00",
    "cause_commit_date": "2023-06-25T23:29:58+00:00",
    "subsystems": [
        "mm"
    ],
    "parent_of_fix_commit": "f66066bc5136f25e36a2daff4896c768f18c211e",
    "patch": "diff --git a/mm/mmap.c b/mm/mmap.c\nindex 51e70fa98450..547b40531791 100644\n--- a/mm/mmap.c\n+++ b/mm/mmap.c\n@@ -2554,11 +2554,10 @@ do_vmi_align_munmap(struct vma_iterator *vmi, struct vm_area_struct *vma,\n \tmas_set(&mas_detach, start);\n \tremove_mt(mm, &mas_detach);\n \t__mt_destroy(&mt_detach);\n+\tvalidate_mm(mm);\n \tif (unlock)\n \t\tmmap_read_unlock(mm);\n \n-\n-\tvalidate_mm(mm);\n \treturn 0;\n \n clear_tree_failed:\n",
    "patch_modified_files": [
        "mm/mmap.c"
    ]
}