[PATCH 1/2] pstore: don't leave an ERR_PTR in the ramoops zone pointer
From: Andrea Parri
Date: Mon Sep 21 2026 - 16:32:59 EST
ramoops_init_prz() stores the result of persistent_ram_new() in *prz and
returns the error without clearing it when initialization fails.
ramoops_probe() then cleans up through ramoops_free_przs(), which hands
*prz to persistent_ram_free(); that treats the ERR_PTR as a valid zone
and dereferences it, crashing the kernel.
Clear *prz before returning so that cleanup sees a NULL zone.
Fixes: b5d38e9bf1b0c ("pstore/ram: Add console messages handling")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Andrea Parri <parri.andrea@xxxxxxxxx>
---
fs/pstore/ram.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/pstore/ram.c b/fs/pstore/ram.c
index 2eb0d4fa21869..aa056d0395a4d 100644
--- a/fs/pstore/ram.c
+++ b/fs/pstore/ram.c
@@ -604,6 +604,7 @@ static int ramoops_init_prz(const char *name,
if (IS_ERR(*prz)) {
int err = PTR_ERR(*prz);
+ *prz = NULL;
dev_err(dev, "failed to request %s mem region (0x%zx@0x%llx): %d\n",
name, sz, (unsigned long long)*paddr, err);
return err;
--
2.53.0