From: sashiko-bot@kernel.org
To: "Coiby Xu" <coiby.xu@gmail.com>
Cc: "Andrew Morton" <akpm@linux-foundation.org>,
"Will Deacon" <will@kernel.org>,
"Baoquan He" <baoquan.he@linux.dev>,
"Jinjie Ruan" <ruanjinjie@huawei.com>,
"Mike Rapoport" <rppt@kernel.org>,
"Randy Dunlap" <rdunlap@infradead.org>,
"Dave Young" <ruirui.yang@linux.dev>,
"Pratyush Yadav" <pratyush@kernel.org>,
linux-arm-kernel@lists.infradead.org,
"Pasha Tatashin" <pasha.tatashin@soleen.com>,
"open list:DOCUMENTATION" <linux-doc@vger.kernel.org>,
kexec@lists.infradead.org,
"Sourabh Jain" <sourabhjain@linux.ibm.com>,
"Jonathan Corbet" <corbet@lwn.net>,
"Shuah Khan" <skhan@linuxfoundation.org>,
"open list" <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH v5 8/9] crash_dump: Disallow configfs/crash_dm_crypt_key/reuse if crash hotplug supported
Date: Wed, 09 Sep 2026 00:53:42 +0000 [thread overview]
Message-ID: <20260909005342.C11AF1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260909003657.1570544-9-coiby.xu@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [High] Setting `image->dm_crypt_keys_addr = 0` during kexec image cleanup bypasses page table memory protections, leaving sensitive dm-crypt volume logon keys accessible/readable in the primary kernel's memory.
Pre-existing issues:
- [High] Reused dm-crypt keys are permanently lost and silently dropped during ARM64 kexec segment placement retries due to premature freeing of `keys_header`.
--
commit ccd76380ffc2464293abaa1bf7ed098e55227890
Author: Coiby Xu <coiby.xu@gmail.com>
crash_dump: Disallow configfs/crash_dm_crypt_key/reuse if crash hotplug supported
If crash hotplug is supported, dm-crypt keys saved to reserved memory
will be taken care of automatically. Thus it doesn't make sense to use
configfs/crash_dm_crypt_key/reuse. Not reserving
image->dm_crypt_keys_addr makes it implicitly to disallow using this
API. Currently x86_64 and ppc64le have implemented crash hotplug
feature.
Also update the doc accordingly. Note two doc issues are fixed as well.
> diff --git a/kernel/crash_dump_dm_crypt.c b/kernel/crash_dump_dm_crypt.c
> index bc70fbb79e0f6..666c1f0c9e3b4 100644
> --- a/kernel/crash_dump_dm_crypt.c
> +++ b/kernel/crash_dump_dm_crypt.c
[ ... ]
> @@ -522,14 +522,18 @@ int crash_load_dm_crypt_keys(struct kimage *image)
> void crash_dm_crypt_cleanup(struct kimage *image)
> {
> /*
> - * For CPU/memory hot-plugging, the kdump image will be reloaded. Prevent
> - * keys_header from being cleaned up during unloading when
> - * is_dm_key_reused=true
> + * For CPU/memory hot-plugging without CONFIG_CRASH_HOTPLUG, the whole kdump
> + * image will be reloaded. Prevent keys_header from being cleaned up during
> + * unloading when is_dm_key_reused=true
> */
> if (!is_dm_key_reused) {
[Severity: High]
This is a pre-existing issue, but can reused dm-crypt keys be permanently
lost during ARM64 kexec segment placement retries due to premature freeing
of keys_header?
On ARM64, if the first kexec segment placement attempt succeeds for dm-crypt
keys but fails on a subsequent segment (like initrd), it triggers a retry
loop. On the first pass, crash_load_dm_crypt_keys() unsets the
is_dm_key_reused flag:
kernel/crash_dump_dm_crypt.c:crash_load_dm_crypt_keys() {
...
out:
is_dm_key_reused = false;
return r;
}
The error path then calls crash_dm_crypt_cleanup(), which unconditionally
frees keys_header since the flag is now false:
arch/arm64/kernel/kexec_image.c:image_load() {
...
image->nr_segments -= 1;
kbuf.buf_min = kernel_segment->mem + kernel_segment->memsz;
kbuf.mem = KEXEC_BUF_MEM_UNKNOWN;
crash_dm_crypt_cleanup(image);
...
}
On the next iteration, crash_load_dm_crypt_keys() is called again but exits
early without allocating keys, leaving the crash kernel without decryption
keys.
> kfree_sensitive(keys_header);
> keys_header = NULL;
> }
> +#ifdef CONFIG_CRASH_HOTPLUG
> + if (image->hotplug_support)
> + image->dm_crypt_keys_addr = 0;
[Severity: High]
Does setting image->dm_crypt_keys_addr to 0 bypass page table memory
protections, leaving sensitive dm-crypt volume logon keys accessible in the
primary kernel's memory?
When crash_dm_crypt_cleanup() is called during kexec file load, it zeroes
image->dm_crypt_keys_addr. Subsequently, sys_kexec_file_load() applies
memory protections:
kernel/kexec_file.c:sys_kexec_file_load() {
...
kimage_file_post_load_cleanup(image);
exchange:
image = xchg(dest_image, image);
out:
#ifdef CONFIG_CRASH_DUMP
if ((flags & KEXEC_FILE_ON_CRASH) && kexec_crash_image)
arch_kexec_protect_crashkres();
...
}
Immediately afterward, kexec_mark_dm_crypt_keys() (called by
arch_kexec_protect_crashkres()) checks this address:
arch/x86/kernel/machine_kexec_64.c:kexec_mark_dm_crypt_keys() {
...
if (kexec_crash_image->dm_crypt_keys_addr) {
start_paddr = kexec_crash_image->dm_crypt_keys_addr;
...
set_memory_np(...);
...
}
Since the address evaluates to 0, it completely skips applying the
non-present page table protections (set_memory_np()), exposing decryption
keys in system RAM.
> +#endif
> }
>
> static int __init configfs_dmcrypt_keys_init(void)
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260909003657.1570544-1-coiby.xu@gmail.com?part=8
next prev parent reply other threads:[~2026-09-09 0:53 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 0:36 [PATCH v5 0/9] Bug fixes and enhancements for kdump LUKS support Coiby Xu
2026-09-09 0:36 ` [PATCH v5 1/9] crash_dump: Fix potential double free and UAF of keys_header Coiby Xu
2026-09-09 0:53 ` sashiko-bot
2026-09-09 13:27 ` Coiby Xu
2026-09-09 0:36 ` [PATCH v5 2/9] crash_dump: Read the number of dm-crypt keys from reserved memory Coiby Xu
2026-09-09 0:52 ` sashiko-bot
2026-09-09 0:36 ` [PATCH v5 3/9] crash_dump: Disallow writing to dm-crypt configfs during kexec_file_load syscall Coiby Xu
2026-09-09 0:47 ` sashiko-bot
2026-09-09 13:29 ` Coiby Xu
2026-09-09 0:36 ` [PATCH v5 4/9] crash_dump: Free temporary dm-crypt keys_header buffer in kdump kernel Coiby Xu
2026-09-09 0:46 ` sashiko-bot
2026-09-09 0:36 ` [PATCH v5 5/9] crash_dump: Only use kexec_dprintk during the kexec_file_load syscall Coiby Xu
2026-09-09 0:47 ` sashiko-bot
2026-09-09 0:36 ` [PATCH v5 6/9] crash_dump: Improve readability of config_keys_restore_store Coiby Xu
2026-09-09 0:45 ` sashiko-bot
2026-09-09 0:36 ` [PATCH v5 7/9] crash_dump: Check the function return codes in restore_dm_crypt_keys_to_thread_keyring Coiby Xu
2026-09-09 0:49 ` sashiko-bot
2026-09-09 0:36 ` [PATCH v5 8/9] crash_dump: Disallow configfs/crash_dm_crypt_key/reuse if crash hotplug supported Coiby Xu
2026-09-09 0:53 ` sashiko-bot [this message]
2026-09-09 5:46 ` Randy Dunlap
2026-09-09 13:33 ` Coiby Xu
2026-09-09 0:36 ` [PATCH v5 9/9] Documentation: kdump: Add arm64 and ppc64le to encrypted dump target support list Coiby Xu
2026-09-09 0:38 ` sashiko-bot
2026-09-09 5:48 ` Randy Dunlap
2026-09-09 13:34 ` Coiby Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909005342.C11AF1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=baoquan.he@linux.dev \
--cc=coiby.xu@gmail.com \
--cc=corbet@lwn.net \
--cc=kexec@lists.infradead.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pasha.tatashin@soleen.com \
--cc=pratyush@kernel.org \
--cc=rdunlap@infradead.org \
--cc=rppt@kernel.org \
--cc=ruanjinjie@huawei.com \
--cc=ruirui.yang@linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=skhan@linuxfoundation.org \
--cc=sourabhjain@linux.ibm.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.