All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eslam Khafagy <eslam.medhat1993@gmail.com>
To: anna-maria@linutronix.de, frederic@kernel.org,
	tglx@linutronix.de, gorcunov@gmail.com
Cc: eslam.medhat1993@gmail.com, syzkaller-bugs@googlegroups.com,
	linux-kernel@vger.kernel.org,
	syzbot+9c47ad18f978d4394986@syzkaller.appspotmail.com
Subject: [PATCH] posix-timers: Fix potential memory leak in do_timer_create()
Date: Fri, 14 Nov 2025 07:06:21 +0200	[thread overview]
Message-ID: <20251114050621.875131-1-eslam.medhat1993@gmail.com> (raw)

potential memory leak may happen if user space pointer created_timer_id
is invallid. or the value it points to is invalid. the call will
prematurely return.

However it doesn't free the memory it allocates with
alloc_posix_timer(). This patch attemps to fix that.

Reported-and-tested-by: syzbot+9c47ad18f978d4394986@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/69155df4.a70a0220.3124cb.0017.GAE@google.com/T/
Fixes: ec2d0c04624b3c8a7eb1682e006717fa20cfbe24 ("posix-timers: Provide a mechanism to allocate a given timer ID")
Signed-off-by: Eslam Khafagy <eslam.medhat1993@gmail.com>
---
 kernel/time/posix-timers.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/kernel/time/posix-timers.c b/kernel/time/posix-timers.c
index aa3120104a51..46ee10551c63 100644
--- a/kernel/time/posix-timers.c
+++ b/kernel/time/posix-timers.c
@@ -483,11 +483,15 @@ static int do_timer_create(clockid_t which_clock, struct sigevent *event,
 
 	/* Special case for CRIU to restore timers with a given timer ID. */
 	if (unlikely(current->signal->timer_create_restore_ids)) {
-		if (copy_from_user(&req_id, created_timer_id, sizeof(req_id)))
+		if (copy_from_user(&req_id, created_timer_id, sizeof(req_id))) {
+			posixtimer_free_timer(new_timer);
 			return -EFAULT;
+		}
 		/* Valid IDs are 0..INT_MAX */
-		if ((unsigned int)req_id > INT_MAX)
+		if ((unsigned int)req_id > INT_MAX) {
+			posixtimer_free_timer(new_timer);
 			return -EINVAL;
+		}
 	}
 
 	/*
-- 
2.43.0


             reply	other threads:[~2025-11-14  5:06 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-11-14  5:06 Eslam Khafagy [this message]
2025-11-14  9:29 ` [PATCH] posix-timers: Fix potential memory leak in do_timer_create() Cyrill Gorcunov
2025-11-14 11:53   ` Eslam Khafagy

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20251114050621.875131-1-eslam.medhat1993@gmail.com \
    --to=eslam.medhat1993@gmail.com \
    --cc=anna-maria@linutronix.de \
    --cc=frederic@kernel.org \
    --cc=gorcunov@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzbot+9c47ad18f978d4394986@syzkaller.appspotmail.com \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=tglx@linutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.