[PATCH] kexec: Fix uninitialized struct kimage *image pointer
Baoquan He
bhe at redhat.com
Fri Dec 12 02:53:15 PST 2025
On 12/12/25 at 03:16pm, Qiang Ma wrote:
> The image is initialized to NULL. Then, after calling kimage_alloc_init,
> we can directly goto 'out' because at this time, the kimage_free will
> determine whether image is a NULL pointer.
Rechecked the code flow, in kimage_alloc_init(), if anything wrong, the
allocated memory are all freed via out_free_control_pages and
out_free_image accordingly, any place missed? If no, I think the current
code is correctly handled.
>
> Signed-off-by: Qiang Ma <maqianga at uniontech.com>
> ---
> kernel/kexec.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
Acked-by: Baoquan He <bhe at redhat.com>
>
> diff --git a/kernel/kexec.c b/kernel/kexec.c
> index 28008e3d462e..9bb1f2b6b268 100644
> --- a/kernel/kexec.c
> +++ b/kernel/kexec.c
> @@ -95,6 +95,8 @@ static int do_kexec_load(unsigned long entry, unsigned long nr_segments,
> unsigned long i;
> int ret;
>
> + image = NULL;
> +
> /*
> * Because we write directly to the reserved memory region when loading
> * crash kernels we need a serialization here to prevent multiple crash
> @@ -129,7 +131,7 @@ static int do_kexec_load(unsigned long entry, unsigned long nr_segments,
>
> ret = kimage_alloc_init(&image, entry, nr_segments, segments, flags);
> if (ret)
> - goto out_unlock;
> + goto out;
>
> if (flags & KEXEC_PRESERVE_CONTEXT)
> image->preserve_context = 1;
> --
> 2.20.1
>
More information about the kexec
mailing list