[PATCH v5 08/17] LoongArch: kexec_file: Fix a modified_cmdline leak
Jinjie Ruan
ruanjinjie at huawei.com
Fri Sep 18 03:04:33 PDT 2026
load_other_segments() allocates modified_cmdline and stores it in
image->arch.cmdline_ptr. machine_kexec_prepare() then copies it to
KEXEC_CMDLINE_ADDR and overwrites the pointer, so the heap buffer is
leaked on every successful kexec_file_load().
Free the buffer after the copy.
Cc: Huacai Chen <chenhuacai at kernel.org>
Cc: WANG Xuerui <kernel at xen0n.name>
Cc: Kexin Liu <liukexin at kylinos.cn>
Cc: Youling Tang <tangyouling at kylinos.cn>
Cc: Qiang Ma <maqianga at uniontech.com>
Cc: Tianyang Zhang <zhangtianyang at loongson.cn>
Cc: George Guo <guodongtai at kylinos.cn>
Cc: stable at vger.kernel.org
Fixes: d162feec6b6e ("LoongArch: Add preparatory infrastructure for kexec_file")
Signed-off-by: Jinjie Ruan <ruanjinjie at huawei.com>
---
arch/loongarch/kernel/machine_kexec.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/loongarch/kernel/machine_kexec.c b/arch/loongarch/kernel/machine_kexec.c
index 1883cae93bc3..19ccc91b6f2a 100644
--- a/arch/loongarch/kernel/machine_kexec.c
+++ b/arch/loongarch/kernel/machine_kexec.c
@@ -14,6 +14,7 @@
#include <linux/mm.h>
#include <linux/of_fdt.h>
#include <linux/reboot.h>
+#include <linux/slab.h>
#include <linux/sched.h>
#include <linux/sched/task_stack.h>
@@ -56,6 +57,7 @@ int machine_kexec_prepare(struct kimage *kimage)
*/
memcpy((void *)KEXEC_CMDLINE_ADDR, (void *)kimage->arch.cmdline_ptr,
strlen((char *)kimage->arch.cmdline_ptr) + 1);
+ kfree((void *)kimage->arch.cmdline_ptr);
kimage->arch.cmdline_ptr = (unsigned long)KEXEC_CMDLINE_ADDR;
} else {
/* Find the command line */
--
2.34.1
More information about the kexec
mailing list