Commit 1d42d57d authored by Peter Oberparleiter's avatar Peter Oberparleiter Committed by Li Nan
Browse files

s390/sclp: Prevent release of buffer in I/O

stable inclusion
from stable-v5.10.224
commit a3e52a4c22c846858a6875e1c280030a3849e148
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAOXYK
CVE: CVE-2024-44969

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=a3e52a4c22c846858a6875e1c280030a3849e148



--------------------------------

[ Upstream commit bf365071ea92b9579d5a272679b74052a5643e35 ]

When a task waiting for completion of a Store Data operation is
interrupted, an attempt is made to halt this operation. If this attempt
fails due to a hardware or firmware problem, there is a chance that the
SCLP facility might store data into buffers referenced by the original
operation at a later time.

Handle this situation by not releasing the referenced data buffers if
the halt attempt fails. For current use cases, this might result in a
leak of few pages of memory in case of a rare hardware/firmware
malfunction.

Reviewed-by: default avatarHeiko Carstens <hca@linux.ibm.com>
Signed-off-by: default avatarPeter Oberparleiter <oberpar@linux.ibm.com>
Signed-off-by: default avatarAlexander Gordeev <agordeev@linux.ibm.com>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarLi Nan <linan122@huawei.com>
parent fe7027c3
Loading
Loading
Loading
Loading
+8 −2
Original line number Diff line number Diff line
@@ -319,8 +319,14 @@ static int sclp_sd_store_data(struct sclp_sd_data *result, u8 di)
			  &esize);
	if (rc) {
		/* Cancel running request if interrupted */
		if (rc == -ERESTARTSYS)
			sclp_sd_sync(page, SD_EQ_HALT, di, 0, 0, NULL, NULL);
		if (rc == -ERESTARTSYS) {
			if (sclp_sd_sync(page, SD_EQ_HALT, di, 0, 0, NULL, NULL)) {
				pr_warn("Could not stop Store Data request - leaking at least %zu bytes\n",
					(size_t)dsize * PAGE_SIZE);
				data = NULL;
				asce = 0;
			}
		}
		vfree(data);
		goto out;
	}