[PATCH] modules/kmod: Allocate argv with kmalloc_array()
From: Kees Cook
Date: Thu Sep 17 2026 - 17:12:42 EST
From: Kees Cook <kees+treewide@xxxxxxxxxx>
In preparation for converting the kmalloc family of allocators to the
type-aware kmalloc_obj family, we need to make sure that the returned
type from the allocation matches the type of the variable being
assigned. (The kmalloc family returns "void *", which can be implicitly
cast to any pointer type.)
argv holds 5 pointers, but the size was taken from the array type
"char *[5]", which would make the allocation type a pointer to that
array rather than the "char **" being assigned. Allocate 5 entries of
the target's type instead. The resulting allocation size is the same.
Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0:
kernel/module/kmod.o
Assisted-by: LLM coccinelle
Signed-off-by: Kees Cook <kees+treewide@xxxxxxxxxx>
---
Cc: Luis Chamberlain <mcgrof@xxxxxxxxxx>
Cc: Petr Pavlu <petr.pavlu@xxxxxxxx>
Cc: Daniel Gomez <da.gomez@xxxxxxxxxx>
Cc: Sami Tolvanen <samitolvanen@xxxxxxxxxx>
Cc: Aaron Tomlin <atomlin@xxxxxxxxxxx>
Cc: <linux-modules@xxxxxxxxxxxxxxx>
---
kernel/module/kmod.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/module/kmod.c b/kernel/module/kmod.c
index a25dccdf7aa7..c19b14c68de5 100644
--- a/kernel/module/kmod.c
+++ b/kernel/module/kmod.c
@@ -81,7 +81,7 @@ static int call_modprobe(char *orig_module_name, int wait)
char *module_name;
int ret;
- char **argv = kmalloc(sizeof(char *[5]), GFP_KERNEL);
+ char **argv = kmalloc_array(5, sizeof(*argv), GFP_KERNEL);
if (!argv)
goto out;
--
2.34.1