]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
mshv_vtl: clear hypercall output before copyout
authorYousef Alhouseen <alhouseenyousef@gmail.com>
Thu, 25 Jun 2026 18:13:14 +0000 (20:13 +0200)
committerWei Liu <wei.liu@kernel.org>
Wed, 22 Jul 2026 23:51:04 +0000 (23:51 +0000)
mshv_vtl_hvcall_call() copies output_size bytes to userspace.

The output page is freshly allocated. Userspace chooses the copyout length.

If the hypercall writes less, the tail can contain stale page data.

Clear the copied range before issuing the hypercall.

Also check both bounce page allocations before either page is used.

Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Reviewed-by: Michael Kelley <mhklinux@outlook.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
drivers/hv/mshv_vtl_main.c

index 0d3d4161974f8ba4a72724f35f8892c43f909a10..dbf03b6676cde0d685fd1129844640d848fde83b 100644 (file)
@@ -1148,12 +1148,22 @@ static int mshv_vtl_hvcall_call(struct mshv_vtl_hvcall_fd *fd,
         */
        in = (void *)__get_free_page(GFP_KERNEL);
        out = (void *)__get_free_page(GFP_KERNEL);
+       if (!in || !out) {
+               ret = -ENOMEM;
+               goto free_pages;
+       }
 
        if (copy_from_user(in, (void __user *)hvcall.input_ptr, hvcall.input_size)) {
                ret = -EFAULT;
                goto free_pages;
        }
 
+       /*
+        * The caller supplies output_size, so clear the range copied back to
+        * userspace in case the hypercall writes fewer bytes than requested.
+        */
+       memset(out, 0, hvcall.output_size);
+
        hvcall.status = hv_do_hypercall(hvcall.control, in, out);
 
        if (copy_to_user((void __user *)hvcall.output_ptr, out, hvcall.output_size)) {