From mboxrd@z Thu Jan 1 00:00:00 1970 From: Paolo Bonzini Subject: Re: [PATCH] Fix NULL dereference in gfn_to_hva_prot() Date: Tue, 01 Oct 2013 19:03:03 +0200 Message-ID: <524B0047.3080700@redhat.com> References: <20131001165836.GX11993@redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: kvm@vger.kernel.org To: Gleb Natapov Return-path: Received: from mx1.redhat.com ([209.132.183.28]:37379 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751128Ab3JARCp (ORCPT ); Tue, 1 Oct 2013 13:02:45 -0400 Received: from int-mx10.intmail.prod.int.phx2.redhat.com (int-mx10.intmail.prod.int.phx2.redhat.com [10.5.11.23]) by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id r91H2jWV022491 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Tue, 1 Oct 2013 13:02:45 -0400 In-Reply-To: <20131001165836.GX11993@redhat.com> Sender: kvm-owner@vger.kernel.org List-ID: Il 01/10/2013 18:58, Gleb Natapov ha scritto: > gfn_to_memslot() can return NULL or invalid slot. We need to check slot > validity before accessing it. > > Signed-off-by: Gleb Natapov > diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c > index 979bff4..a9dd682 100644 > --- a/virt/kvm/kvm_main.c > +++ b/virt/kvm/kvm_main.c > @@ -1064,10 +1064,12 @@ EXPORT_SYMBOL_GPL(gfn_to_hva); > unsigned long gfn_to_hva_prot(struct kvm *kvm, gfn_t gfn, bool *writable) > { > struct kvm_memory_slot *slot = gfn_to_memslot(kvm, gfn); > - if (writable) > + unsigned long hva = __gfn_to_hva_many(slot, gfn, NULL, false); > + > + if (!kvm_is_error_hva(hva) && writable) > *writable = !memslot_is_readonly(slot); > > - return __gfn_to_hva_many(gfn_to_memslot(kvm, gfn), gfn, NULL, false); > + return hva; > } > > static int kvm_read_hva(void *data, void __user *hva, int len) > -- > Gleb. > Reviewed-by: Paolo Bonzini