From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6A3DE434E50 for ; Wed, 12 Aug 2026 11:32:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=82.195.75.108 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786534338; cv=none; b=uKJ78QxYqwc42jx3D4EnkeoflDbnRDC5DCMhOsxxB/wrNL7crS70tLNHvAT7fug5S8bz2a/3q89EubzkZqSWZZpP87O1f4W2UF4phjKmPoMmCV4dE/2wfaOzB9l3TqYlFFxBsDUHhByVexvFs5A2kxrABK/qZG3W7wuIk2ZPG6s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786534338; c=relaxed/simple; bh=FmvGEkh2rRrjTsnxxpplsZ7+GnyJWiiOZt1q+BoClXI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=PO8aDXOAuGZ3DmKHArcmNx9Tx07HTYce7auk4PkdhZXs8gKvjgKhne9Zu9C7vIy3flb9L95pAO1lNqvEGsC9DmNTQt2JgFY3hPj5VCXoxHP2+QUecF1bSmPJzdfBJIiwZvTAFLvWKh/19wCSFkEpFaywlY7T+0oLiom8LfP1ZTo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=debian.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b=Bgkzq1hs; arc=none smtp.client-ip=82.195.75.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=debian.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="Bgkzq1hs" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Cc:To:In-Reply-To:References: Message-Id:Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date: From:Reply-To:Content-ID:Content-Description; bh=96LAzBjfGAx9nfZL8SX73XYEA1A5G1phryUkEZQ35/w=; b=Bgkzq1hsvSlzCUSnGj2E/Lk8tY 1dMyAR9AzJbQC4LpK1CNVMN3IMg2XiBBdGGpHkZxiyzZHzvIp3lUvfGekHCX5qso78dVIIz/RZzCU hVvG+mObEJqzW7JMq1qj9/03SAiuonCVJ7bOj/yPU94AS13q/qPSjmQLbpm0nHqqRNDSL9GTfJTki 7cfn0GrGjen4rSZ9S7hRf+NKHoJNEtW8bP6rjSgwUqTSuMZ4Tvjn4LUfe7bBvffBhNfU4VO18ZqA4 jZM4srYTplz+S6iuZ0U3OAwuI7bklGXi8w3NpWly3ODPPkf2aua3U5d1w/Dfozz2IlQpJhZVdTTkj YSjXuH3g==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1wu7Bo-004JJH-16; Wed, 12 Aug 2026 11:32:08 +0000 From: Breno Leitao Date: Wed, 12 Aug 2026 04:31:51 -0700 Subject: [PATCH v6 1/2] kexec_file: stop the top-down search before it underflows Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260812-kexec_posioned-v6-1-e477887086f0@debian.org> References: <20260812-kexec_posioned-v6-0-e477887086f0@debian.org> In-Reply-To: <20260812-kexec_posioned-v6-0-e477887086f0@debian.org> To: Andrew Morton , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Baoquan He , Pasha Tatashin , Pratyush Yadav , Miaohe Lin , Naoya Horiguchi Cc: Breno Leitao , linux-mm@kvack.org, linux-kernel@vger.kernel.org, kexec@lists.infradead.org, rmikey@meta.com, riel@surriel.com, kernel-team@meta.com X-Mailer: b4 0.16-dev-f8e9d X-Developer-Signature: v=1; a=openpgp-sha256; l=1669; i=leitao@debian.org; h=from:subject:message-id; bh=FmvGEkh2rRrjTsnxxpplsZ7+GnyJWiiOZt1q+BoClXI=; b=owEBbQKS/ZANAwAIATWjk5/8eHdtAcsmYgBqfFmsyEno7+ZM8jNDTttS6/P8qtEqZPqoheexT 8D0MQRonQuJAjMEAAEIAB0WIQSshTmm6PRnAspKQ5s1o5Of/Hh3bQUCanxZrAAKCRA1o5Of/Hh3 bXSJD/9jfrIbSU3oHTQv0L6n64XBO1LZMWRmaCcv4mpdb64PYKBuJ1vpA5i8Tqe5xgTSKXXA23c CuwqNJzcw1l3YXFoQsX3nttO24qrXYmd1hXK/jlkiBlgRxi+K3ue/Xmcz9108cNsRdieQmwVc6A h7veNRxUviUn1rvqU4UrdmgY5FZC5phM5rnABwFMz/hOju74BJ2YBer7UB23/KC81X5lPomJxQu DjRMiHU5OgXRDphVIdC1ehkv6d+D4L+kv2WGaJDqJ6qA6QsFScNowu+jY+WIbq+7nO2VY0RooHp IUm06Yv2t0eN2jtT05X0mve/wbxwzrHerIWupYY15hnhalruDg4iPLEv0UER95+Z28F/c7LpfXe 8a6LbuH6JVQSr/lfxxoNSoqSatUe0YEGHWNecjZS85BdNG1pqw3mmN5N/1z9hxNC2KpPXtQXwSe nkAhZCovOV5Lnma3VIV4uFACGpv1O7NjkHsPX/xjEl/saVEWhnZW+Kk4/n577us+SJbLXQW+0Lm N1imHnRQQYBGccSPA8iyjrYOZhhJdUxEbGuISLllYItLB+g5UzJdx8wvHro047EPIzHVqffnTe8 gofvKGUZtDyNj0/gzahda+W8EGVLlfGHHnyUE1bA3xQDQIiiTfONMjN28AA3hd0JGadH48d7q1+ sSI7+Vo85i3O9sw== X-Developer-Key: i=leitao@debian.org; a=openpgp; fpr=AC8539A6E8F46702CA4A439B35A3939FFC78776D X-Debian-User: leitao locate_mem_hole_top_down() walks candidates downwards by subtracting PAGE_SIZE whenever the window conflicts with an existing segment or with an architecture exclude range. Nothing stops that subtraction at zero, so a search that reaches the bottom of the address space wraps temp_start around and continues. The walk starts inside the range being scanned and only moves down, so bail out once a candidate ends up above end. That covers every step in the loop rather than the subtractions alone, and it matches locate_mem_hole_bottom_up(), which already bounds its candidate on both sides. This is a better check than subtracting with check_sub_overflow(), given that we would have 3 subtractions in this block, and this single fix would take care of them all (instead of three check_sub_overflow()). Fixes: cb1052581e2b ("kexec: implementation of new syscall kexec_file_load") Signed-off-by: Breno Leitao --- kernel/kexec_file.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/kernel/kexec_file.c b/kernel/kexec_file.c index 59fb9d71e9d86..01a64d98fbcd7 100644 --- a/kernel/kexec_file.c +++ b/kernel/kexec_file.c @@ -484,7 +484,9 @@ static int locate_mem_hole_top_down(unsigned long start, unsigned long end, /* align down start */ temp_start = ALIGN_DOWN(temp_start, kbuf->buf_align); - if (temp_start < start || temp_start < kbuf->buf_min) + /* A candidate above the range means the walk wrapped around */ + if (temp_start < start || temp_start < kbuf->buf_min || + temp_start > end) return 0; temp_end = temp_start + kbuf->memsz - 1; -- 2.53.0-Meta