> If load_other_segments() fails after image->elf_headers is assigned,
> the memory lifecycle is safely managed by the global kimage object
> and will be freed in arch_kimage_file_post_load_cleanup().
> 
> However, during a retry loop in efi_kexec_load(), a subsequent iteration
> will allocate a new buffer and overwrite image->elf_headers. This
> permanently leaks the stale memory from the previous iteration before
> the global cleanup can track it.
> 
> Fix this by explicitly freeing the stale `image->elf_headers` buffer
> before assigning the newly allocated headers.
> 
> Cc: Huacai Chen <[email protected]>
> Cc: WANG Xuerui <[email protected]>
> Cc: Youling Tang <[email protected]>
> Cc: "Mike Rapoport (Microsoft)" <[email protected]>
> Cc: Sourabh Jain <[email protected]>
> Cc: Kees Cook <[email protected]>
> Cc: [email protected]
> Link: 
> https://sashiko.dev/#/patchset/20260729031235.2840255-1-ruanjinjie%40huawei.com
> Fixes: 55d990f0084c ("LoongArch: Add EFI binary support for kexec_file")
> Signed-off-by: Jinjie Ruan <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=7


Reply via email to