[PATCH master 2/4] tlsf: unpoison whole block in malloc_usable_size()
Ahmad Fatoum
a.fatoum at pengutronix.de
Mon Aug 24 04:59:56 PDT 2026
malloc_usable_size() tells the caller how many bytes beyond the
originally requested size may be accessed, but TLSF only unpoisons the
requested size, leaving the padding up to the block size poisoned.
free_sensitive() zeroes the whole usable size, so with CONFIG_KASAN
enabled, freeing sensitive memory whose size is not a multiple of the
poisoning granule falsely reports a use-after-poison in
memzero_explicit().
Unpoison the whole block when its usable size is queried, so callers
can do what the API promises.
Fixes: 0af97b298266 ("malloc: implement free_sensitive()")
Assisted-by: Claude:fable-5
Signed-off-by: Ahmad Fatoum <a.fatoum at pengutronix.de>
---
common/tlsf_malloc.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/common/tlsf_malloc.c b/common/tlsf_malloc.c
index 36fdc307cc26..8315073105cc 100644
--- a/common/tlsf_malloc.c
+++ b/common/tlsf_malloc.c
@@ -52,7 +52,16 @@ EXPORT_SYMBOL(free);
size_t malloc_usable_size(void *mem)
{
- return tlsf_block_size(mem);
+ size_t size = tlsf_block_size(mem);
+
+ /*
+ * Callers like free_sensitive() may access the whole usable
+ * size, so unpoison the padding beyond the requested size.
+ */
+ if (size)
+ kasan_unpoison_shadow(mem, size);
+
+ return size;
}
EXPORT_SYMBOL(malloc_usable_size);
--
2.47.3
More information about the barebox
mailing list