From: Andi Kleen Date: Tue, 8 Dec 2009 12:19:42 +0000 (+0100) Subject: futex: Take mmap_sem for get_user_pages in fault_in_user_writeable X-Git-Tag: firefly_0821_release~11625^2~576 X-Git-Url: http://demsky.eecs.uci.edu/git/?a=commitdiff_plain;h=bb2fb5d6a16840cf98af1a5d405a583c200d87a8;p=firefly-linux-kernel-4.4.55.git futex: Take mmap_sem for get_user_pages in fault_in_user_writeable commit 722d0172377a5697919b9f7e5beb95165b1dec4e upstream. get_user_pages() must be called with mmap_sem held. Signed-off-by: Andi Kleen Cc: Andrew Morton Cc: Nick Piggin Cc: Darren Hart Cc: Peter Zijlstra LKML-Reference: <20091208121942.GA21298@basil.fritz.box> Signed-off-by: Thomas Gleixner Signed-off-by: Greg Kroah-Hartman --- diff --git a/kernel/futex.c b/kernel/futex.c index fb65e822fc41..d73ef1f3e55d 100644 --- a/kernel/futex.c +++ b/kernel/futex.c @@ -304,8 +304,14 @@ void put_futex_key(int fshared, union futex_key *key) */ static int fault_in_user_writeable(u32 __user *uaddr) { - int ret = get_user_pages(current, current->mm, (unsigned long)uaddr, - 1, 1, 0, NULL, NULL); + struct mm_struct *mm = current->mm; + int ret; + + down_read(&mm->mmap_sem); + ret = get_user_pages(current, mm, (unsigned long)uaddr, + 1, 1, 0, NULL, NULL); + up_read(&mm->mmap_sem); + return ret < 0 ? ret : 0; }