[PATCH] mm/slub: initialize the free pointer of the bootstrap kmem_cache_node
From: Karl Mehltretter
Date: Sat Oct 10 2026 - 16:39:18 EST
With slub_debug=FZPU, validating kmem_cache_node reports
BUG kmem_cache_node (Not tainted): Freepointer corrupt
Object 0xffff888000140040 @offset=64 fp=0x5a5a5a5a5a5a5a5a
and taints the kernel. Poisoning places the bootstrap object's free
pointer outside the object, where check_object() checks it even while
allocated.
early_kmem_cache_node_alloc() previously took this object from a
freelist with an initialized pointer. It now takes it from the slab
iterator and builds the freelist only for the remaining objects,
leaving its pointer filled with POISON_INUSE.
Initialize the bootstrap object's free pointer to NULL.
Fixes: dc795d4c0282 ("mm/slub: defer freelist construction until after bulk allocation from a new slab")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@xxxxxxxxx>
---
QEMU x86_64 and custom QEMU SH7785LCR model, slub_debug=FZPU:
validation reports "Freepointer corrupt" before the fix, clean after.
mm/slub.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/mm/slub.c b/mm/slub.c
index 54ec125033571..9a20aa820bb0f 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -7777,6 +7777,7 @@ static void early_kmem_cache_node_alloc(int node)
n = next_slab_obj(kmem_cache_node, &iter);
BUG_ON(!n);
+ set_freepointer(kmem_cache_node, n, NULL);
slab->inuse = 1;
build_slab_freelist(kmem_cache_node, slab, &iter);
--
2.53.0