From: Coiby Xu <coiby.xu@gmail.com>
To: kexec@lists.infradead.org
Cc: Andrew Morton <akpm@linux-foundation.org>,
Sourabh Jain <sourabhjain@linux.ibm.com>,
Baoquan He <baoquan.he@linux.dev>,
Dave Young <ruirui.yang@linux.dev>,
Pratyush Yadav <pratyush@kernel.org>,
Mike Rapoport <rppt@kernel.org>,
Pasha Tatashin <pasha.tatashin@soleen.com>,
linux-kernel@vger.kernel.org (open list)
Subject: [PATCH v4 4/9] crash_dump: Free temporary dm-crypt keys_header buffer in kdump kernel
Date: Fri, 28 Aug 2026 16:48:50 +0800 [thread overview]
Message-ID: <20260828084900.1496839-5-coiby.xu@gmail.com> (raw)
In-Reply-To: <20260828084900.1496839-1-coiby.xu@gmail.com>
Although we expect the system to reboot immediately after vmcore dumping
is finished, it's still good to free the temporary keys_header buffer.
Fixes: 62f17d9df692 ("crash_dump: retrieve dm crypt keys in kdump kernel")
Reported-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Coiby Xu <coiby.xu@gmail.com>
---
kernel/crash_dump_dm_crypt.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/kernel/crash_dump_dm_crypt.c b/kernel/crash_dump_dm_crypt.c
index 0b9e09c60745..91b7a5413b62 100644
--- a/kernel/crash_dump_dm_crypt.c
+++ b/kernel/crash_dump_dm_crypt.c
@@ -118,6 +118,7 @@ static int get_keys_from_kdump_reserved_memory(void)
static int restore_dm_crypt_keys_to_thread_keyring(void)
{
+ struct keys_header *keys_header __free(kfree_sensitive) = NULL;
struct dm_crypt_key *key;
size_t keys_header_size;
key_ref_t keyring_ref;
--
2.55.0
next prev parent reply other threads:[~2026-08-28 8:49 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-28 8:48 [PATCH v4 0/9] Bug fixes and enhancements for kdump LUKS support Coiby Xu
2026-08-28 8:48 ` [PATCH v4 1/9] crash_dump: Fix potential double free and UAF of keys_header Coiby Xu
2026-08-30 6:30 ` Sourabh Jain
2026-08-31 13:39 ` Coiby Xu
2026-08-30 7:07 ` Sourabh Jain
2026-08-31 7:39 ` Jinjie Ruan
2026-08-31 13:44 ` Coiby Xu
2026-09-01 1:36 ` Jinjie Ruan
2026-09-02 12:53 ` Coiby Xu
2026-08-28 8:48 ` [PATCH v4 2/9] crash_dump: Disallow writing to dm-crypt configfs during kexec_file_load syscall Coiby Xu
2026-08-29 7:02 ` Sourabh Jain
2026-08-29 12:17 ` Coiby Xu
2026-08-30 5:37 ` Sourabh Jain
2026-08-28 8:48 ` [PATCH v4 3/9] crash_dump: Read the number of dm-crypt keys from reserved memory Coiby Xu
2026-08-30 7:19 ` Sourabh Jain
2026-08-31 13:45 ` Coiby Xu
2026-08-28 8:48 ` Coiby Xu [this message]
2026-08-28 8:48 ` [PATCH v4 5/9] crash_dump: Only use kexec_dprintk during the kexec_file_load syscall Coiby Xu
2026-08-28 8:48 ` [PATCH v4 6/9] crash_dump: Improve readability of config_keys_restore_store Coiby Xu
2026-08-28 8:48 ` [PATCH v4 7/9] crash_dump: Check the function return codes in restore_dm_crypt_keys_to_thread_keyring Coiby Xu
2026-08-28 8:48 ` [PATCH v4 8/9] crash_dump: Disallow configfs/crash_dm_crypt_key/reuse if crash hotplug supported Coiby Xu
2026-08-30 7:58 ` Sourabh Jain
2026-08-31 13:34 ` Coiby Xu
2026-08-28 8:48 ` [PATCH v4 9/9] Documentation: kdump: Add arm64 and ppc64le to encrypted dump target support list Coiby Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260828084900.1496839-5-coiby.xu@gmail.com \
--to=coiby.xu@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=baoquan.he@linux.dev \
--cc=kexec@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pasha.tatashin@soleen.com \
--cc=pratyush@kernel.org \
--cc=rppt@kernel.org \
--cc=ruirui.yang@linux.dev \
--cc=sourabhjain@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox