Re: [PATCH v5 1/9] livepatch: Fix wrong index in funcs cleanup error path

Yafang Shao <[email protected]>
Newsgroups dev.linux.lists.sashiko-reviews,org.kernel.vger.live-patching
Message-ID <CALOAHbD48m1VTLirFrKXgsDs+SAaaU3_PG21NQWbkt5SfH3E+Q@mail.gmail.com>
On Sun, Aug 9, 2026 at 5:28 PM <[email protected]> wrote:
>
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] The patch introduces a double free vulnerability on the `funcs` allocation error path.
> --
>
> --- Patch [1]: [PATCH v5 1/9] livepatch: Fix wrong index in funcs cleanup error path ---
> commit c03811c85b7c79e0d681d9978c346e4424c48a99
> Author: Yafang Shao <[email protected]>
>
> livepatch: Fix wrong index in funcs cleanup error path
>
> This commit modifies the cleanup loop in livepatch_mod_init() to use the
> index j instead of i when kzalloc() fails for a function array. This
> attempts to prevent leaking previously allocated function arrays.
>
> > diff --git a/scripts/livepatch/init.c b/scripts/livepatch/init.c
> > index f14d8c8fb35fa..16aff8f736eb6 100644
> > --- a/scripts/livepatch/init.c
> > +++ b/scripts/livepatch/init.c
> > @@ -51,7 +51,7 @@ static int __init livepatch_mod_init(void)
> >               if (!funcs) {
> >                       ret = -ENOMEM;
> >                       for (int j = 0; j < i; j++)
> > -                             kfree(objs[i].funcs);
> > +                             kfree(objs[j].funcs);
>
> [Severity: High]
> Does this introduce a double free in livepatch_mod_init()?
>
> When the inner loop here frees objs[j].funcs, it leaves the dangling pointer
> in the objs array. The code then jumps to err_free_objs, which iterates over
> all objects and frees the arrays again:
>
> err_free_objs:
>         for (int i = 0; i < nr_objs; i++)
>                 kfree(objs[i].funcs);
>
> Since the pointers weren't set to NULL in the inner loop, won't the
> err_free_objs cleanup loop free the identical memory allocations a
> second time?

This is an invalid review issue. Since kfree(objs[i].funcs) is not
added to err_free_objs in the current state, and it is moved from its
current place to err_free_objs in patch #4.

-- 
Regards
Yafang
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.