Re: [PATCH] mm: rmap: fix use-after-free in __put_anon_vma

2014-06-06 Thread Andrey Ryabinin
On 06/06/14 15:56, Peter Zijlstra wrote: > On Fri, Jun 06, 2014 at 03:30:55PM +0400, Andrey Ryabinin wrote: >> While working address sanitizer for kernel I've discovered use-after-free >> bug in __put_anon_vma. >> For the last anon_vma, anon_vma->root freed before child anon_vma. >> Later in anon_v

Re: [PATCH] mm: rmap: fix use-after-free in __put_anon_vma

2014-06-06 Thread Peter Zijlstra
On Fri, Jun 06, 2014 at 03:30:55PM +0400, Andrey Ryabinin wrote: > While working address sanitizer for kernel I've discovered use-after-free > bug in __put_anon_vma. > For the last anon_vma, anon_vma->root freed before child anon_vma. > Later in anon_vma_free(anon_vma) we are referencing to already