From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Message-Id: <20111018103126.963744783@de.ibm.com> Date: Tue, 18 Oct 2011 12:27:12 +0200 From: Christian Borntraeger To: Avi Kivity , Marcelo Tossati Cc: Carsten Otte , Heiko Carstens , Martin Schwidefsky , KVM , , Christian Borntraeger Subject: [patch 1/4] kvm-s390: check cpu_id prior to using it References: <20111018102711.259185287@de.ibm.com> Content-Disposition: inline; filename=500-kvm-check-cpuid.diff Sender: kvm-owner@vger.kernel.org List-ID: From: Carsten Otte We use the cpu id provided by userspace as array index here. Thus we clearly need to check it first. Ooops. CC: Signed-off-by: Carsten Otte Signed-off-by: Christian Borntraeger --- arch/s390/kvm/kvm-s390.c | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) Index: b/arch/s390/kvm/kvm-s390.c =================================================================== --- a/arch/s390/kvm/kvm-s390.c +++ b/arch/s390/kvm/kvm-s390.c @@ -312,11 +312,17 @@ int kvm_arch_vcpu_setup(struct kvm_vcpu struct kvm_vcpu *kvm_arch_vcpu_create(struct kvm *kvm, unsigned int id) { - struct kvm_vcpu *vcpu = kzalloc(sizeof(struct kvm_vcpu), GFP_KERNEL); - int rc = -ENOMEM; + struct kvm_vcpu *vcpu; + int rc = -EINVAL; + if (id >= KVM_MAX_VCPUS) + goto out; + + rc = -ENOMEM; + + vcpu = kzalloc(sizeof(struct kvm_vcpu), GFP_KERNEL); if (!vcpu) - goto out_nomem; + goto out; vcpu->arch.sie_block = (struct kvm_s390_sie_block *) get_zeroed_page(GFP_KERNEL); @@ -352,7 +358,7 @@ out_free_sie_block: free_page((unsigned long)(vcpu->arch.sie_block)); out_free_cpu: kfree(vcpu); -out_nomem: +out: return ERR_PTR(rc); }