[PATCH] riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove

Paul Walmsley pjw at kernel.org
Wed Jul 29 16:37:59 PDT 2026


On Wed, 29 Jul 2026, Karl Mehltretter wrote:

> remove_pud_mapping() and remove_p4d_mapping() obtain a child table base
> with pud_offset(p4dp, 0) and p4d_offset(pgd, 0), then add the index for
> addr.
> 
> RISC-V folds page-table levels at runtime. When a level is folded, its
> offset helper returns the parent entry itself, but the index can still be
> nonzero. Adding it walks past the parent table. Sv48 folds P4D, while Sv39
> folds both P4D and PUD, so memory hot-remove can descend into unrelated
> memory and pass an invalid page to __free_pages(). This can trigger:
> 
>   kernel BUG at include/linux/mm.h:1810!
>   VM_BUG_ON_PAGE(page_ref_count(page) == 0)
>   arch_remove_memory+0x1e/0x5c
>   try_remove_memory+0x15e/0x200
>   remove_memory+0x24/0x3c
> 
> Only add the index when the corresponding page-table level is enabled,
> matching p4d_offset() and pud_offset().
> 
> Fixes: c75a74f4ba19 ("riscv: mm: Add memory hotplugging support")
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Karl Mehltretter <kmehltretter at gmail.com>

Thanks, queued for v7.2-rc.


- Paul



More information about the linux-riscv mailing list