mirror of
https://github.com/torvalds/linux.git
synced 2026-09-28 03:52:02 +02:00
KVM: s390: Fix old_data leak in guest debug error path
__import_wp_info() allocates a per-watchpoint old_data buffer to back up
the original guest memory contents. If a later watchpoint of the same
KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data()
jumps to the error label, which frees the wp_info array but not the
old_data buffers of the entries that were imported successfully. Up to
MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed
request, and the request can be repeated.
Create error handling for cleaning up all created old_data memory
areas.
Fixes: 27291e2165 ("KVM: s390: hardware support for guest debugging")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-6-borntraeger@linux.ibm.com>
This commit is contained in:
parent
121ea1de92
commit
aa9c8e8baf
|
|
@ -252,7 +252,7 @@ int kvm_s390_import_bp_data(struct kvm_vcpu *vcpu,
|
|||
ret = __import_wp_info(vcpu, &bp_data[i],
|
||||
&wp_info[nr_wp]);
|
||||
if (ret)
|
||||
goto error;
|
||||
goto error_wp;
|
||||
nr_wp++;
|
||||
break;
|
||||
case KVM_HW_BP:
|
||||
|
|
@ -269,6 +269,10 @@ int kvm_s390_import_bp_data(struct kvm_vcpu *vcpu,
|
|||
vcpu->arch.guestdbg.hw_wp_info = wp_info;
|
||||
kfree(bp_data);
|
||||
return 0;
|
||||
|
||||
error_wp:
|
||||
while (nr_wp--)
|
||||
kfree(wp_info[nr_wp].old_data);
|
||||
error:
|
||||
kfree(bp_data);
|
||||
kfree(wp_info);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user