[PATCH v3 13/17] crash: Improve elfcorehdr segment identification
From: Jinjie Ruan
Date: Wed Aug 26 2026 - 05:42:27 EST
Only checking ELFMAG is insufficient, as other segments like the
kernel image or an ELF initrd may also start with \x7fELF, leading
to misidentification. This is especially problematic when elfcorehdr
is not the last segment, such as:
kexec -d --t bzImage -p bzImage --initrd=/bin/true
Add an "e_type == ET_CORE" check to ensure the correct segment is
identified, and break early after finding it.
Signed-off-by: Jinjie Ruan <ruanjinjie@xxxxxxxxxx>
---
kernel/crash_core.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/kernel/crash_core.c b/kernel/crash_core.c
index bd3f82b62751..0730c4ea8054 100644
--- a/kernel/crash_core.c
+++ b/kernel/crash_core.c
@@ -737,9 +737,14 @@ static void crash_handle_hotplug_event(unsigned int hp_action, unsigned int cpu,
mem = image->segment[n].mem;
ptr = kmap_local_page(pfn_to_page(mem >> PAGE_SHIFT));
if (ptr) {
+ Elf64_Ehdr *ehdr = (Elf64_Ehdr *)ptr;
+
/* The segment containing elfcorehdr */
- if (memcmp(ptr, ELFMAG, SELFMAG) == 0)
+ if (memcmp(ptr, ELFMAG, SELFMAG) == 0 && ehdr->e_type == ET_CORE) {
image->elfcorehdr_index = (int)n;
+ kunmap_local(ptr);
+ break;
+ }
kunmap_local(ptr);
}
}
--
2.34.1