From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f169.google.com (mail-yw1-f169.google.com [209.85.128.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F138D3DCD9B for ; Wed, 24 Jun 2026 17:22:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782321762; cv=none; b=u3p4iBsKRMuAxuiZr2NL1mLp5uRPN66EYE+TKxox1gYMA8spTurobLzWHbplIOtg5xaM/f65oVvrc0kg114vN5kXTw5pQvMmEx6n5H1Oq2VEVF/Mdiwiq2EUImqvOXsKDXdEDzG3yMjJ9FTQ6LYw3S5CEhwS+eGnN+2qt+fLCG8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782321762; c=relaxed/simple; bh=bYdiyUxQ1xXquRm8oNOGsZfeYsTcAGZLZoxdSt1Er28=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=X8lptSF+7Wh4fNhXD9sk333jeD/UMulNGrGZbpY7MN8512n5G9qNUZKgbhNoAqei6Q0PCOMqfgP5akqZ504QKi2LesK8Eh+tT1rqCXbS1hKeuYmLE7JUNMKCSrnGnDe17tvCDf2uHQTREEuUxtjKNbgeEGM9i+EH8tTDnmB+fWw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=eOx3yF/3; arc=none smtp.client-ip=209.85.128.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="eOx3yF/3" Received: by mail-yw1-f169.google.com with SMTP id 00721157ae682-7dd5a8dc8a2so10476767b3.0 for ; Wed, 24 Jun 2026 10:22:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782321759; x=1782926559; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=pbwnK5C4I/+GGTcPtzynJG36TtlPd9rOiV4o4AgC0tU=; b=eOx3yF/3ST4Djc2akpkUeXbEwHHH9rKceut98O+4PVBo6U1TgLm8jxmFpsUJHPyNqh ElAbjAk3MobJSgoznGbNRXT3YjdL+7z5CSWtc5uVYv46iud23dHffeA+GS79LuN7Q5Br wPwrXu5ZWtn1ezAUohAKh6/W+a4mnnlomt6yKTFHJGus5vxifdZGLD1s10+B6/VoB14K xQgpTBy990/gugnTOxhFgBRbQCgXwoaVDuYwlKMHDrjdwxaXdCiJeSy1ImapiDLDIxx6 gLt9Q82/5m4NE+IT3V3xG0/60A+YQcKO54HyxxI0ZfMciwngvP11pRMoaGxVSo+xpxmh vPPg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782321759; x=1782926559; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=pbwnK5C4I/+GGTcPtzynJG36TtlPd9rOiV4o4AgC0tU=; b=Cvi0L7Llhowo/4KtgjGKptfgGsgWA3gMHyBJsm06dtnor+n4BzBtlay75I4xVS6rQX Cb9WvU+k/tNBLxLyCUJpzZqJn81tiyprppTRBe5RETuhXFXTs+xzNgZJVz9hatZd3CBa kUXr2Jg781nFxJJYHbKt/4tyFcPsI8wouOhb76xW1gHa9YHpwcfmJcYXBt6t6b18E5r5 zVfNldzDnKINZ1Z13sCxM7mqtXLUwM3xKwTP8twuVMtlTLNctiv/OUZpMkRvGCaFMaU+ eINfNYezenOlUx8+TKAv+kMoYCyR2TWil9iqzY2SHwuEV3PuO7lT6Oc2jTGvzrq0DbRd x4qw== X-Forwarded-Encrypted: i=1; AHgh+Ro7/Ow4MdlKMg68Nn5VPWam8SFADD+DMI34xBnnJ84FJ2qJzxnrAQssmTch8tcw2q8uqqNtKnvNoaBad/8=@vger.kernel.org X-Gm-Message-State: AOJu0YwM12Da3SIUOSftjr9Ky/FVNKChZ+y7RWVCwLpccf2WapfI2cmI LZTsIxFjhpsgB4EQGnEJr23sqHAxT7XMB6Xp+/7MtLIN0zfwaG3wybgP X-Gm-Gg: AfdE7ckYdo9SJgvwUi+fNDMQUPdtBDKykfJBbJhXTuZJv+dMrv/d56Z7kL1Ajm5brdD 1NAu/1+d4GqmL7ko+Vsp1lzIDhzR8gBK8IisSThFXt7jS4foa0aARTMb3B1L/7aDRZ4j8Ri36Lh l27QO09+EnXPWbMHprfQpFVaGQugv9p7FTL4Jf7GFsl0by+kivBBafk4tw4ddgd+Mt5cKxuncc3 FtciMx3nOl0Cvr4PN6VyluNM1GdYxMmBU/F3HwTFfj76qF9SCpTMG4DXx+3T1WSYpa37+y15lqh yWWhnfD4dZq7qwypTlOAuOuEIsnwST1kcZETVDwr2CRrqfuaUodJqPMTlX8NxQXSsjoVkk5CBip TOLYm1+mdOF5jD0fpTihqOzALEZ2Wz+TT6k6R8fHZ1X5ohYfkimQsIiWPfFpIdg7j8Se7rGrtqR p2u7pFUqjpyXlXer2qzIKet/tRtA== X-Received: by 2002:a05:690c:6885:b0:7f8:7e60:acf with SMTP id 00721157ae682-807ef918a25mr41186257b3.52.1782321758845; Wed, 24 Jun 2026 10:22:38 -0700 (PDT) Received: from Dev-Null-MSI ([2a0d:3344:52ac:a808:98a4:4381:be45:536f]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8025c96fdbesm60985327b3.8.2026.06.24.10.22.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 24 Jun 2026 10:22:38 -0700 (PDT) From: Yousef Alhouseen To: "K . Y . Srinivasan" , Haiyang Zhang , Wei Liu , Dexuan Cui , Long Li Cc: linux-hyperv@vger.kernel.org, linux-kernel@vger.kernel.org, Yousef Alhouseen Subject: [PATCH] hyperv: mshv: zero VTL hypercall output page Date: Wed, 24 Jun 2026 19:21:57 +0200 Message-ID: <20260624172157.2790-1-alhouseenyousef@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit mshv_vtl_hvcall_call() copies output_size bytes from a freshly allocated hypercall output page back to userspace. The page is currently allocated without __GFP_ZERO, so any bytes not written by the hypervisor are copied from stale page contents. Allocate the output page zeroed before issuing the hypercall. Also check both bounce-page allocations before using them so memory pressure cannot turn the copy paths into NULL pointer dereferences. Signed-off-by: Yousef Alhouseen --- drivers/hv/mshv_vtl_main.c | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/drivers/hv/mshv_vtl_main.c b/drivers/hv/mshv_vtl_main.c index 0d3d41619..0365d207c 100644 --- a/drivers/hv/mshv_vtl_main.c +++ b/drivers/hv/mshv_vtl_main.c @@ -1147,7 +1147,11 @@ static int mshv_vtl_hvcall_call(struct mshv_vtl_hvcall_fd *fd, * TODO: Take care of this when CVM support is added. */ in = (void *)__get_free_page(GFP_KERNEL); - out = (void *)__get_free_page(GFP_KERNEL); + out = (void *)__get_free_page(GFP_KERNEL | __GFP_ZERO); + if (!in || !out) { + ret = -ENOMEM; + goto free_pages; + } if (copy_from_user(in, (void __user *)hvcall.input_ptr, hvcall.input_size)) { ret = -EFAULT; @@ -1162,8 +1166,10 @@ static int mshv_vtl_hvcall_call(struct mshv_vtl_hvcall_fd *fd, } ret = put_user(hvcall.status, &hvcall_user->status); free_pages: - free_page((unsigned long)in); - free_page((unsigned long)out); + if (in) + free_page((unsigned long)in); + if (out) + free_page((unsigned long)out); return ret; } -- 2.54.0