x86/crash: fix crash_setup_memmap_entries() KASAN vmalloc-out-of-bounds gripe

[   15.428011] BUG: KASAN: vmalloc-out-of-bounds in 
crash_setup_memmap_entries+0x17e/0x3a0
[   15.428018] Write of size 8 at addr ffffc90000426008 by task kexec/1187

(gdb) list *crash_setup_memmap_entries+0x17e
0xffffffff8107cafe is in crash_setup_memmap_entries 
(arch/x86/kernel/crash.c:322).
317                                      unsigned long long mend)
318     {
319             unsigned long start, end;
320
321             cmem->ranges[0].start = mstart;
322             cmem->ranges[0].end = mend;
323             cmem->nr_ranges = 1;
324
325             /* Exclude elf header region */
326             start = image->arch.elf_load_addr;
(gdb)

We're excluding two ranges, allocate the scratch space we need to do that.

Signed-off-by: Mike Galbraith <efa...@gmx.de>
---
 arch/x86/kernel/crash.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/x86/kernel/crash.c
+++ b/arch/x86/kernel/crash.c
@@ -337,7 +337,7 @@ int crash_setup_memmap_entries(struct ki
        struct crash_memmap_data cmd;
        struct crash_mem *cmem;

-       cmem = vzalloc(sizeof(struct crash_mem));
+       cmem = vzalloc(sizeof(struct crash_mem)+(2*sizeof(struct 
crash_mem_range)));
        if (!cmem)
                return -ENOMEM;


Reply via email to