The patch titled Subject: mm/mmap: fix leak on expand_downwards() and expand_upwards() has been added to the -mm mm-unstable branch. Its filename is mm-start-tracking-vmas-with-maple-tree-fix-2.patch This patch will shortly appear at https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-start-tracking-vmas-with-maple-tree-fix-2.patch This patch will later appear in the mm-unstable branch at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm Before you just go and hit "reply", please: a) Consider who else should be cc'ed b) Prefer to cc a suitable mailing list as well c) Ideally: find the original patch on the mailing list and do a reply-to-all to that, adding suitable additional cc's *** Remember to use Documentation/process/submit-checklist.rst when testing your code *** The -mm tree is included into linux-next via the mm-everything branch at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm and is updated there every 2-3 working days ------------------------------------------------------ From: Liam Howlett <liam.howlett@xxxxxxxxxx> Subject: mm/mmap: fix leak on expand_downwards() and expand_upwards() A memory leak is possible in the race and error path in both expand_downwards() and expand_upwards() due to the maple tree preallocations. Fix these by always destroying the maple state. Link: https://lkml.kernel.org/r/20220512175915.1814885-1-Liam.Howlett@xxxxxxxxxx Fixes: a760774e7b7b (mm: start tracking VMAs with maple tree) Signed-off-by: Liam R. Howlett <Liam.Howlett@xxxxxxxxxx> Reported-by: Qian Cai <quic_qiancai@xxxxxxxxxxx> Cc: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx> Signed-off-by: Andrew Morton <akpm@xxxxxxxxxxxxxxxxxxxx> --- mm/mmap.c | 2 ++ 1 file changed, 2 insertions(+) --- a/mm/mmap.c~mm-start-tracking-vmas-with-maple-tree-fix-2 +++ a/mm/mmap.c @@ -2664,6 +2664,7 @@ int expand_upwards(struct vm_area_struct khugepaged_enter_vma_merge(vma, vma->vm_flags); validate_mm(mm); validate_mm_mt(mm); + mas_destroy(&mas); return error; } #endif /* CONFIG_STACK_GROWSUP || CONFIG_IA64 */ @@ -2751,6 +2752,7 @@ int expand_downwards(struct vm_area_stru anon_vma_unlock_write(vma->anon_vma); khugepaged_enter_vma_merge(vma, vma->vm_flags); validate_mm(mm); + mas_destroy(&mas); return error; } _ Patches currently in -mm which might be from liam.howlett@xxxxxxxxxx are maple-tree-add-new-data-structure-fix.patch lib-test_maple_tree-add-testing-for-maple-tree-fix.patch mm-start-tracking-vmas-with-maple-tree-fix-2.patch