]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
authorFarhan Ali <alifm@linux.ibm.com>
Thu, 23 Jul 2026 22:14:07 +0000 (15:14 -0700)
committerChristian Borntraeger <borntraeger@linux.ibm.com>
Fri, 24 Jul 2026 09:26:54 +0000 (11:26 +0200)
The airq_iv_create() can return NULL on failure, but the return value was
never checked. If it fails, zdev->aibv will be NULL and fail when
dereferenced in kvm_zpci_set_airq(). Add a NULL check and free the
previously allocated AISB bit and zdev->aisb on failure.

Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
arch/s390/kvm/pci.c

index 36eb30953bb59a0a2d34668d3f7dca5b93e4a758..1eb127fc9f8957165c84d017c0d71210ceba3987 100644 (file)
@@ -317,6 +317,11 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
                                    AIRQ_IV_GUESTVEC,
                                    phys_to_virt(fib->fmt0.aibv));
 
+       if (!zdev->aibv) {
+               rc = -ENOMEM;
+               goto free_aisb;
+       }
+
        spin_lock_irq(&aift->gait_lock);
        gaite = aift->gait + zdev->aisb;
 
@@ -353,6 +358,9 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
        rc = kvm_zpci_set_airq(zdev);
        return rc;
 
+free_aisb:
+       airq_iv_free_bit(aift->sbv, zdev->aisb);
+       zdev->aisb = 0;
 unlock:
        if (pcount > 0)
                unaccount_mem(zdev->kzdev, pcount);