Alexander Potapenko
unread,Sep 2, 2026, 5:03:43 AMSep 2Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Liu Jing, el...@google.com, dvy...@google.com, ak...@linux-foundation.org, kasa...@googlegroups.com, linu...@kvack.org, linux-...@vger.kernel.org
On Wed, Sep 2, 2026 at 10:56 AM Liu Jing <
liu...@cmss.chinamobile.com> wrote:
>
> In test_init_vmalloc(), the return value of vmalloc() is used directly
> without a NULL check. If vmalloc() fails under memory pressure, the
> subsequent buf[0] = 1 and memset() calls will dereference a NULL
> pointer and cause a kernel panic.
Out of curiosity, have you actually observed vmalloc() failing under
memory pressure during this test?
> Add a NULL check immediately after vmalloc() and skip the test if
> allocation fails.
>
> Signed-off-by: Liu Jing <
liu...@cmss.chinamobile.com>
> ---
> mm/kmsan/kmsan_test.c | 6 ++++++
> 1 file changed, 6 insertion(+), 0 deletion(-)
>
> --- a/mm/kmsan/kmsan_test.c
> +++ b/mm/kmsan/kmsan_test.c
> @@ -352,6 +352,12 @@
>
> kunit_info(test, "vmalloc buffer can be initialized (no reports)\n");
> buf = vmalloc(PAGE_SIZE * npages);
> +
> + if (!buf) {
> + kunit_skip(test, "vmalloc failed, skipping test\n");
> + return;
> + }
While at it, can you add similar checks to other allocation sites in this file?
The problem is not specific to vmalloc()
> buf[0] = 1;
> memset(buf, 0xfe, PAGE_SIZE * npages);
> USE(buf[0]);
>
> --
> 2.43.0
>
>
--
Alexander Potapenko
Software Engineer
Google Germany GmbH
Erika-Mann-Straße, 33
80636 München
Geschäftsführer: Paul Manicle, Liana Sebastian
Registergericht und -nummer: Hamburg, HRB 86891
Sitz der Gesellschaft: Hamburg