ZeroHour

CVE-2022-50765

CVSS
EPSS
<1%p14
Published
()
Modified
Description

In the Linux kernel, the following vulnerability has been resolved: RISC-V: kexec: Fix memory leak of elf header buffer This is reported by kmemleak detector: unreferenced object 0xff2000000403d000 (size 4096): comm "kexec", pid 146, jiffies 4294900633 (age 64.792s) hex dump (first 32 bytes): 7f 45 4c 46 02 01 01 00 00 00 00 00 00 00 00 00 .ELF............ 04 00 f3 00 01 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [ ] kmemleak_vmalloc+0x3c/0xbe [ ] __vmalloc_node_range+0x3ac/0x560 [ ] __vmalloc_node+0x56/0x62 [ ] vzalloc+0x2c/0x34 [ ] crash_prepare_elf64_headers+0x80/0x30c [ ] elf_kexec_load+0x3e8/0x4ec [ ] kexec_image_load_default+0x40/0x4c [ ] sys_kexec_file_load+0x1c4/0x322 [ ] ret_from_syscall+0x0/0x2 In elf_kexec_load(), a buffer is allocated via vzalloc() to store elf headers. While it's not freed back to system when kdump kernel is reloaded or unloaded, or when image->elf_header is successfully set and then fails to load kdump kernel for some reason. Fix it by freeing the buffer in arch_kimage_file_post_load_cleanup().

In the news

No ingested article mentions this CVE yet.