From 77d1f4f98349899981794ce7920b58f1383dd4ff Mon Sep 17 00:00:00 2001 From: Liu Shixin Date: Wed, 5 Feb 2025 15:04:57 +0800 Subject: [PATCH] mm/compaction: fix UBSAN shift-out-of-bounds warning mainline inclusion from mainline-v6.14-rc1 commit d1366e74342e75555af2648a2964deb2d5c92200 category: bugfix bugzilla: https://gitee.com/openeuler/kernel/issues/IBK3VP CVE: NA Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d1366e74342e75555af2648a2964deb2d5c92200 -------------------------------- syzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order) in isolate_freepages_block(). The bogus compound_order can be any value because it is union with flags. Add back the MAX_PAGE_ORDER check to fix the warning. Link: https://lkml.kernel.org/r/20250123021029.2826736-1-liushixin2@huawei.com Fixes: 3da0272a4c7d ("mm/compaction: correctly return failure with bogus compound_order in strict mode") Signed-off-by: Liu Shixin Reviewed-by: Kemeng Shi Acked-by: David Hildenbrand Reviewed-by: Oscar Salvador Cc: Baolin Wang Cc: David Hildenbrand Cc: Kemeng Shi Cc: Matthew Wilcox Cc: Mel Gorman Cc: Nanyong Sun Cc: Signed-off-by: Andrew Morton Conflicts: mm/compaction.c [ This is partial revert of commit 343e35e561bc. ] Signed-off-by: Liu Shixin --- mm/compaction.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/mm/compaction.c b/mm/compaction.c index 8010521ff969..e7c1ffc23c9a 100644 --- a/mm/compaction.c +++ b/mm/compaction.c @@ -476,7 +476,8 @@ static unsigned long isolate_freepages_block(struct compact_control *cc, if (PageCompound(page)) { const unsigned int order = compound_order(page); - if (blockpfn + (1UL << order) <= end_pfn) { + if (likely(order < MAX_ORDER) && + (blockpfn + (1UL << order) <= end_pfn)) { blockpfn += (1UL << order) - 1; cursor += (1UL << order) - 1; } -- Gitee