Back

bpf: Fix mmap_lock deadlock on arena lock failure

Published Sep 17, 2026

Description

Reported by the Sashiko AI review.

arena_vm_fault() returns VM_FAULT_RETRY when it can't take arena->spinlock, but it never took mmap_lock. The fault path assumes a VM_FAULT_RETRY handler already dropped mmap_lock and re-takes it on the retry, so mmap_lock gets taken twice and can deadlock:

do_user_addr_fault() { fault = handle_mm_fault(...); // calls arena_vm_fault() if (fault & VM_FAULT_RETRY) goto retry; // re-locks mmap_lock mmap_read_unlock(mm); }

Return VM_FAULT_SIGBUS instead, for two reasons:

1. We could keep VM_FAULT_RETRY, but then we'd have to drop the fault lock first and cap the retry ourselves, the way __folio_lock_or_retry() does.

2. A failed raw_res_spin_lock_irqsave() already means a possible deadlock was detected, so retrying just hits the same lock again.

So returning VM_FAULT_RETRY here is overkill.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Sep 17, 2026
Updated Sep 17, 2026
Reserved Sep 11, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Sep 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Linux
Published Sep 17, 2026
Updated Sep 17, 2026

GitHub

No data