)]}'
{
  "commit": "dccb9898113653219d0460cefd449aaddc8bb0b5",
  "tree": "fd72f3da023c0be880003879f144bc2f010c4e97",
  "parents": [
    "41e4311faf623ee461a20d329b76ab780c1df596"
  ],
  "author": {
    "name": "Jakub Acs",
    "email": "acsjakub@amazon.de",
    "time": "Wed Oct 01 09:03:52 2025 +0000"
  },
  "committer": {
    "name": "Angel Adetula",
    "email": "angeladetula@google.com",
    "time": "Mon Nov 10 23:41:17 2025 -0800"
  },
  "message": "mm/ksm: fix flag-dropping behavior in ksm_madvise\n\ncommit f04aad36a07cc17b7a5d5b9a2d386ce6fae63e93 upstream.\n\nsyzkaller discovered the following crash: (kernel BUG)\n\n[   44.607039] ------------[ cut here ]------------\n[   44.607422] kernel BUG at mm/userfaultfd.c:2067!\n[   44.608148] Oops: invalid opcode: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI\n[   44.608814] CPU: 1 UID: 0 PID: 2475 Comm: reproducer Not tainted 6.16.0-rc6 #1 PREEMPT(none)\n[   44.609635] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n[   44.610695] RIP: 0010:userfaultfd_release_all+0x3a8/0x460\n\n\u003csnip other registers, drop unreliable trace\u003e\n\n[   44.617726] Call Trace:\n[   44.617926]  \u003cTASK\u003e\n[   44.619284]  userfaultfd_release+0xef/0x1b0\n[   44.620976]  __fput+0x3f9/0xb60\n[   44.621240]  fput_close_sync+0x110/0x210\n[   44.622222]  __x64_sys_close+0x8f/0x120\n[   44.622530]  do_syscall_64+0x5b/0x2f0\n[   44.622840]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[   44.623244] RIP: 0033:0x7f365bb3f227\n\nKernel panics because it detects UFFD inconsistency during\nuserfaultfd_release_all().  Specifically, a VMA which has a valid pointer\nto vma-\u003evm_userfaultfd_ctx, but no UFFD flags in vma-\u003evm_flags.\n\nThe inconsistency is caused in ksm_madvise(): when user calls madvise()\nwith MADV_UNMEARGEABLE on a VMA that is registered for UFFD in MINOR mode,\nit accidentally clears all flags stored in the upper 32 bits of\nvma-\u003evm_flags.\n\nAssuming x86_64 kernel build, unsigned long is 64-bit and unsigned int and\nint are 32-bit wide.  This setup causes the following mishap during the \u0026\u003d\n~VM_MERGEABLE assignment.\n\nVM_MERGEABLE is a 32-bit constant of type unsigned int, 0x8000\u00270000.\nAfter ~ is applied, it becomes 0x7fff\u0027ffff unsigned int, which is then\npromoted to unsigned long before the \u0026 operation.  This promotion fills\nupper 32 bits with leading 0s, as we\u0027re doing unsigned conversion (and\neven for a signed conversion, this wouldn\u0027t help as the leading bit is 0).\n\u0026 operation thus ends up AND-ing vm_flags with 0x0000\u00270000\u00277fff\u0027ffff\ninstead of intended 0xffff\u0027ffff\u00277fff\u0027ffff and hence accidentally clears\nthe upper 32-bits of its value.\n\nFix it by changing `VM_MERGEABLE` constant to unsigned long, using the\nBIT() macro.\n\nNote: other VM_* flags are not affected: This only happens to the\nVM_MERGEABLE flag, as the other VM_* flags are all constants of type int\nand after ~ operation, they end up with leading 1 and are thus converted\nto unsigned long with leading 1s.\n\nNote 2:\nAfter commit 31defc3b01d9 (\"userfaultfd: remove (VM_)BUG_ON()s\"), this is\nno longer a kernel BUG, but a WARNING at the same place:\n\n[   45.595973] WARNING: CPU: 1 PID: 2474 at mm/userfaultfd.c:2067\n\nbut the root-cause (flag-drop) remains the same.\n\n[akpm@linux-foundation.org: rust bindgen wasn\u0027t able to handle BIT(), from Miguel]\n  Link: https://lore.kernel.org/oe-kbuild-all/202510030449.VfSaAjvd-lkp@intel.com/\nBUG\u003db/456102261\nTEST\u003dpresubmit\nRELEASE_NOTE\u003dFixed CVE-2025-40040 in the Linux kernel.\n\ncos-patch: security-moderate\nLink: https://lkml.kernel.org/r/20251001090353.57523-2-acsjakub@amazon.de\nFixes: 7677f7fd8be7 (\"userfaultfd: add minor fault registration mode\")\nChange-Id: I06758d4f4ec98ee0509fddfe849cf0e0c144749f\nSigned-off-by: Jakub Acs \u003cacsjakub@amazon.de\u003e\nSigned-off-by: Miguel Ojeda \u003cmiguel.ojeda.sandonis@gmail.com\u003e\nAcked-by: David Hildenbrand \u003cdavid@redhat.com\u003e\nAcked-by: SeongJae Park \u003csj@kernel.org\u003e\nTested-by: Alice Ryhl \u003caliceryhl@google.com\u003e\nTested-by: Miguel Ojeda \u003cmiguel.ojeda.sandonis@gmail.com\u003e\nCc: Xu Xin \u003cxu.xin16@zte.com.cn\u003e\nCc: Chengming Zhou \u003cchengming.zhou@linux.dev\u003e\nCc: Peter Xu \u003cpeterx@redhat.com\u003e\nCc: Axel Rasmussen \u003caxelrasmussen@google.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\n[acsjakub@amazon.de: adapt rust bindgen to older versions]\nSigned-off-by: Jakub Acs \u003cacsjakub@amazon.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Kernel CVE Triage Automation \u003ccloud-image-kernel-cve-triage-automation@prod.google.com\u003e\nReviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/117667\nReviewed-by: Angel Adetula \u003cangeladetula@google.com\u003e\nReviewed-by: Kevin Berry \u003ckpberry@google.com\u003e\nTested-by: Cusky Presubmit Bot \u003cpresubmit@cos-infra-prod.iam.gserviceaccount.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "2be90c9c77c4781ddc66793b0d2a5527213e2885",
      "old_mode": 33188,
      "old_path": "include/linux/mm.h",
      "new_id": "852f8d35bd1420dd4042446b753fa4fc1579e0a4",
      "new_mode": 33188,
      "new_path": "include/linux/mm.h"
    },
    {
      "type": "modify",
      "old_id": "fdb4e11df3bd3bf8b0b713d342e644168a635f64",
      "old_mode": 33188,
      "old_path": "rust/bindings/bindings_helper.h",
      "new_id": "2f5fd797955a396f5df704712fab46f15ec50bf0",
      "new_mode": 33188,
      "new_path": "rust/bindings/bindings_helper.h"
    },
    {
      "type": "modify",
      "old_id": "6c50ee62c56b6ee2d210b963b5c26d615134e884",
      "old_mode": 33188,
      "old_path": "rust/bindings/lib.rs",
      "new_id": "8cf84e899817c6c617423b4b72a212017c1e3619",
      "new_mode": 33188,
      "new_path": "rust/bindings/lib.rs"
    }
  ]
}
