[PATCH 6/8] arm64: kexec_file: Fix image->elf_headers memory leak during retry loop

Jinjie Ruan <[email protected]>
Newsgroups org.ozlabs.lists.linuxppc-dev,org.infradead.lists.kexec,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Sashiko AI code review pointed out a potential memory leak of
image->elf_headers when load_other_segments() fails on error paths.

When load_other_segments() fails during the arm64 kexec_file file-load
path, execution jumps to the out_err label. While this path restores
`image->nr_segments`, it returns an error back to the caller without
freeing the allocated `image->elf_headers` vmalloc buffer.

Consequently, the retry loop in image_load() will allocate new ELF
headers on the next iteration and overwrite `image->elf_headers`,
permanently leaking the memory blocks allocated in previous iterations.

Fix this by explicitly freeing the stale `image->elf_headers` buffer
once the new headers buffer is allocated.

Cc: Catalin Marinas <[email protected]>
Cc: Will Deacon <[email protected]>
Cc: Thomas Huth <[email protected]>
Cc: Breno Leitao <[email protected]>
Cc: Andrew Morton <[email protected]>
Cc: Yeoreum Yun <[email protected]>
Cc: Coiby Xu <[email protected]>
Cc: Baoquan He <[email protected]>
Cc: Kees Cook <[email protected]>
Cc: Benjamin Gwin <[email protected]>
Cc: [email protected]
Fixes: 108aa503657e ("arm64: kexec_file: try more regions if loading segments fails")
Signed-off-by: Jinjie Ruan <[email protected]>
---
 arch/arm64/kernel/machine_kexec_file.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/arch/arm64/kernel/machine_kexec_file.c b/arch/arm64/kernel/machine_kexec_file.c
index e48f29167b38..2f750e5f4fcc 100644
--- a/arch/arm64/kernel/machine_kexec_file.c
+++ b/arch/arm64/kernel/machine_kexec_file.c
@@ -112,6 +112,10 @@ int load_other_segments(struct kimage *image,
 			vfree(headers);
 			goto out_err;
 		}
+
+		if (unlikely(image->elf_headers))
+			vfree(image->elf_headers);
+
 		image->elf_headers = headers;
 		image->elf_load_addr = kbuf.mem;
 		image->elf_headers_sz = headers_sz;
-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.