提交 f8c1b85b 编写于 作者: P Paolo Bonzini 提交者: Radim Krčmář

KVM: x86: avoid vmalloc(0) in the KVM_SET_CPUID

This causes an ugly dmesg splat.  Beautified syzkaller testcase:

    #include <unistd.h>
    #include <sys/syscall.h>
    #include <sys/ioctl.h>
    #include <fcntl.h>
    #include <linux/kvm.h>

    long r[8];

    int main()
    {
        struct kvm_irq_routing ir = { 0 };
        r[2] = open("/dev/kvm", O_RDWR);
        r[3] = ioctl(r[2], KVM_CREATE_VM, 0);
        r[4] = ioctl(r[3], KVM_SET_GSI_ROUTING, &ir);
        return 0;
    }
Reported-by: NDmitry Vyukov <dvyukov@google.com>
Signed-off-by: NPaolo Bonzini <pbonzini@redhat.com>
Signed-off-by: NRadim Krčmář <rkrcmar@redhat.com>
上级 c622a3c2
...@@ -2935,7 +2935,7 @@ static long kvm_vm_ioctl(struct file *filp, ...@@ -2935,7 +2935,7 @@ static long kvm_vm_ioctl(struct file *filp,
case KVM_SET_GSI_ROUTING: { case KVM_SET_GSI_ROUTING: {
struct kvm_irq_routing routing; struct kvm_irq_routing routing;
struct kvm_irq_routing __user *urouting; struct kvm_irq_routing __user *urouting;
struct kvm_irq_routing_entry *entries; struct kvm_irq_routing_entry *entries = NULL;
r = -EFAULT; r = -EFAULT;
if (copy_from_user(&routing, argp, sizeof(routing))) if (copy_from_user(&routing, argp, sizeof(routing)))
...@@ -2945,15 +2945,17 @@ static long kvm_vm_ioctl(struct file *filp, ...@@ -2945,15 +2945,17 @@ static long kvm_vm_ioctl(struct file *filp,
goto out; goto out;
if (routing.flags) if (routing.flags)
goto out; goto out;
r = -ENOMEM; if (routing.nr) {
entries = vmalloc(routing.nr * sizeof(*entries)); r = -ENOMEM;
if (!entries) entries = vmalloc(routing.nr * sizeof(*entries));
goto out; if (!entries)
r = -EFAULT; goto out;
urouting = argp; r = -EFAULT;
if (copy_from_user(entries, urouting->entries, urouting = argp;
routing.nr * sizeof(*entries))) if (copy_from_user(entries, urouting->entries,
goto out_free_irq_routing; routing.nr * sizeof(*entries)))
goto out_free_irq_routing;
}
r = kvm_set_irq_routing(kvm, entries, routing.nr, r = kvm_set_irq_routing(kvm, entries, routing.nr,
routing.flags); routing.flags);
out_free_irq_routing: out_free_irq_routing:
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册