bpf: Fix mmap_lock deadlock on arena lock failure
Published Sep 17, 2026
No CVSS score
EPSS 0.20%
Description
Reported by the Sashiko AI review.
arena_vm_fault() returns VM_FAULT_RETRY when it can't take arena->spinlock, but it never took mmap_lock. The fault path assumes a VM_FAULT_RETRY handler already dropped mmap_lock and re-takes it on the retry, so mmap_lock gets taken twice and can deadlock:
do_user_addr_fault() { fault = handle_mm_fault(...); // calls arena_vm_fault() if (fault & VM_FAULT_RETRY) goto retry; // re-locks mmap_lock mmap_read_unlock(mm); }
Return VM_FAULT_SIGBUS instead, for two reasons:
1. We could keep VM_FAULT_RETRY, but then we'd have to drop the fault lock first and cap the retry ourselves, the way __folio_lock_or_retry() does.
2. A failed raw_res_spin_lock_irqsave() already means a possible deadlock was detected, so retrying just hits the same lock again.
So returning VM_FAULT_RETRY here is overkill.
Affected products
-
Affected
- ≥ , <
- ≥ , <
-
Affected
- 7.0
Unaffected
- ≥ 0, < 7.0
- ≥ 7.2.6, ≤ 7.2.*
- 7.3-rc1
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (3)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data