]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in pmcmd_ioctl
authorHaoyu Li <lihaoyu499@gmail.com>
Thu, 30 Jan 2025 11:58:11 +0000 (19:58 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 13 Mar 2025 11:51:11 +0000 (12:51 +0100)
commit4e15cf870d2c748e45d45ffc4d5b1dc1b7d50120
tree71a18a4b1c49827b4b4585b1ff492f1907ee2ecc
parentade9362dec1856bb349aefcb6477f76aad7b04c7
drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in pmcmd_ioctl

commit 819cec1dc47cdeac8f5dd6ba81c1dbee2a68c3bb upstream.

In the "pmcmd_ioctl" function, three memory objects allocated by
kmalloc are initialized by "hcall_get_cpu_state", which are then
copied to user space. The initializer is indeed implemented in
"acrn_hypercall2" (arch/x86/include/asm/acrn.h). There is a risk of
information leakage due to uninitialized bytes.

Fixes: 3d679d5aec64 ("virt: acrn: Introduce interfaces to query C-states and P-states allowed by hypervisor")
Signed-off-by: Haoyu Li <lihaoyu499@gmail.com>
Cc: stable <stable@kernel.org>
Acked-by: Fei Li <fei1.li@intel.com>
Link: https://lore.kernel.org/r/20250130115811.92424-1-lihaoyu499@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/virt/acrn/hsm.c