On Fri, 4 Nov 2022 17:25:19 -0400 Seth Jenkins <sethjenkins@xxxxxxxxxx> wrote: > Commit e4a0d3e720e7 ("aio: Make it possible to remap aio ring") introduced > a null-deref if mremap is called on an old aio mapping after fork as > mm->ioctx_table will be set to NULL. > Is this a theoretical thing, or has this oops actually been observed?