Skip to content

Commit d337f45

Browse files
fuqiang wangakpm00
authored andcommitted
x86/kexec: fix potential cmem->ranges out of memory
In memmap_exclude_ranges(), elfheader will be excluded from crashk_res. In the current x86 architecture code, the elfheader is always allocated at crashk_res.start. It seems that there won't be a new split range. But it depends on the allocation position of elfheader in crashk_res. To avoid potential out of memory in future, add a extra slot. Otherwise loading the kdump kernel will fail because crash_exclude_mem_range will return -ENOMEM. random kexec_buf for passing dm crypt keys may cause a range split too, add another extra slot here. The similar issue also exists in fill_up_crash_elf_data(). The range to be excluded is [0, 1M], start (0) is special and will not appear in the middle of existing cmem->ranges[]. But in cast the low 1M could be changed in the future, add a extra slot too. Previous discussions: [1] https://lore.kernel.org/kexec/ZXk2oBf%2FT1Ul6o0c@MiWiFi-R3L-srv/ [2] https://lore.kernel.org/kexec/273284e8-7680-4f5f-8065-c5d780987e59@easystack.cn/ [3] https://lore.kernel.org/kexec/ZYQ6O%2F57sHAPxTHm@MiWiFi-R3L-srv/ Link: https://lkml.kernel.org/r/20250904093855.1180154-1-coxu@redhat.com Signed-off-by: fuqiang wang <fuqiang.wang@easystack.cn> Signed-off-by: Baoquan He <bhe@redhat.com> Signed-off-by: Coiby Xu <coxu@redhat.com> Cc: Dave Young <dyoung@redhat.com> Cc: Vivek Goyal <vgoyal@redhat.com> Cc: Borislav Betkov <bp@alien8.de> Cc: "H. Peter Anvin" <hpa@zytor.com> Cc: Ingo Molnar <mingo@redhat.com> Cc: Thomas Gleinxer <tglx@linutronix.de> Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
1 parent 13f2353 commit d337f45

1 file changed

Lines changed: 19 additions & 4 deletions

File tree

arch/x86/kernel/crash.c

Lines changed: 19 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -165,8 +165,18 @@ static struct crash_mem *fill_up_crash_elf_data(void)
165165
/*
166166
* Exclusion of crash region, crashk_low_res and/or crashk_cma_ranges
167167
* may cause range splits. So add extra slots here.
168+
*
169+
* Exclusion of low 1M may not cause another range split, because the
170+
* range of exclude is [0, 1M] and the condition for splitting a new
171+
* region is that the start, end parameters are both in a certain
172+
* existing region in cmem and cannot be equal to existing region's
173+
* start or end. Obviously, the start of [0, 1M] cannot meet this
174+
* condition.
175+
*
176+
* But in order to lest the low 1M could be changed in the future,
177+
* (e.g. [start, 1M]), add a extra slot.
168178
*/
169-
nr_ranges += 2 + crashk_cma_cnt;
179+
nr_ranges += 3 + crashk_cma_cnt;
170180
cmem = vzalloc(struct_size(cmem, ranges, nr_ranges));
171181
if (!cmem)
172182
return NULL;
@@ -322,10 +332,15 @@ int crash_setup_memmap_entries(struct kimage *image, struct boot_params *params)
322332
struct crash_mem *cmem;
323333

324334
/*
325-
* Using random kexec_buf for passing dm crypt keys may cause a range
326-
* split. So use two slots here.
335+
* In the current x86 architecture code, the elfheader is always
336+
* allocated at crashk_res.start. But it depends on the allocation
337+
* position of elfheader in crashk_res. To avoid potential out of
338+
* bounds in future, add an extra slot.
339+
*
340+
* And using random kexec_buf for passing dm crypt keys may cause a
341+
* range split too, add another extra slot here.
327342
*/
328-
nr_ranges = 2;
343+
nr_ranges = 3;
329344
cmem = vzalloc(struct_size(cmem, ranges, nr_ranges));
330345
if (!cmem)
331346
return -ENOMEM;

0 commit comments

Comments
 (0)