[PATCH] mm/slub: initialize the free pointer of the bootstrap kmem_cache_node

From: Karl Mehltretter

Date: Sat Oct 10 2026 - 16:39:18 EST


With slub_debug=FZPU, validating kmem_cache_node reports

BUG kmem_cache_node (Not tainted): Freepointer corrupt
Object 0xffff888000140040 @offset=64 fp=0x5a5a5a5a5a5a5a5a

and taints the kernel. Poisoning places the bootstrap object's free
pointer outside the object, where check_object() checks it even while
allocated.

early_kmem_cache_node_alloc() previously took this object from a
freelist with an initialized pointer. It now takes it from the slab
iterator and builds the freelist only for the remaining objects,
leaving its pointer filled with POISON_INUSE.

Initialize the bootstrap object's free pointer to NULL.

Fixes: dc795d4c0282 ("mm/slub: defer freelist construction until after bulk allocation from a new slab")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@xxxxxxxxx>
---
QEMU x86_64 and custom QEMU SH7785LCR model, slub_debug=FZPU:
validation reports "Freepointer corrupt" before the fix, clean after.

mm/slub.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/mm/slub.c b/mm/slub.c
index 54ec125033571..9a20aa820bb0f 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -7777,6 +7777,7 @@ static void early_kmem_cache_node_alloc(int node)

n = next_slab_obj(kmem_cache_node, &iter);
BUG_ON(!n);
+ set_freepointer(kmem_cache_node, n, NULL);

slab->inuse = 1;
build_slab_freelist(kmem_cache_node, slab, &iter);
--
2.53.0