[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v2 1/6] dt-overlay: Fix NULL pointer dereference


  • To: <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Michal Orzel <michal.orzel@xxxxxxx>
  • Date: Fri, 4 Oct 2024 14:22:15 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=lists.xenproject.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=qMyZSSKtyxLWnjqInD9m5eg0zHWpnF3h8hQyllg0PFs=; b=GzijKEmIRS2lmTWcqW69Q924y+/jz3gJ78IrQ3DMMzShMSBUyDsQhEx/BlyCBqDHrmJqYUGwx2dVVqQCgqwkYT6KBIgjygCTwKoNU7trQcMdWsPPOxDFPTQM3s3MHqpPO/iKlFpUMqP1XGHIJVZ1If7+rvWKk8X9jnkCBWTVAZJvJrc9PUGycNxkn5zw9aBkgUfoAI9uxIE8Q9cSj9qJqWxK1NBoieOY1dBz+tlDHbq5zVCEhn745PDhyat/INyT2rQ7awCX1Q2xkUrJpOTu7MiRNRRWtKf23JYkyPSz8Dsw2IfjqbJPDuXRTc72Mi58qwRFM00Kn2VOnWASGVePTA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=aVZDilnPaD0TTCjTngS3ozjRnMypmu98wOGs8mAv2SfHFhdkMoLLx61ogDxnj/UACLOw6A/SkePhYjciUbWAXoTTI3x6rzaoskgbSfeOYA4ly9HieaWDEQMat5yv7DmuHACaWSxjZCd8dNUXf4t0vz76/WdCj1IYjZ6CrzoYF6aGOVnj6zxWpNGNWlfPJz+w8GQVlo8SIjJc0yXvcw+gVnX+fCAT2j1ROkgL61dQ9Uyy6GCPSvadRGUV5uDvr5f5gIOg8hGCcIDtHJN1IyH64UAhvGJAuUVCfWCotlPAt44YBH/zse/hKb/sJmtaoMLwp5YakUGcJ7XdhQggVk59EA==
  • Cc: Michal Orzel <michal.orzel@xxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>
  • Delivery-date: Fri, 04 Oct 2024 12:22:51 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

Attempt to attach an overlay (xl dt-overlay attach) to a domain without
first adding this overlay to Xen (xl dt-overlay add) results in an
overlay track entry being NULL in handle_attach_overlay_nodes(). This
leads to NULL pointer dereference and the following data abort crash:

(XEN) Cannot find any matching tracker with input dtbo. Operation is supported 
only for prior added dtbo.
(XEN) Data Abort Trap. Syndrome=0x5
(XEN) Walking Hypervisor VA 0x40 on CPU0 via TTBR 0x0000000046948000
(XEN) 0TH[0x000] = 0x46940f7f
(XEN) 1ST[0x000] = 0x0
(XEN) CPU0: Unexpected Trap: Data Abort
(XEN) ----[ Xen-4.20-unstable  arm64  debug=y  Not tainted ]----
...
(XEN) Xen call trace:
(XEN)    [<00000a0000208b30>] dt_overlay_domctl+0x304/0x370 (PC)
(XEN)    [<00000a0000208b30>] dt_overlay_domctl+0x304/0x370 (LR)
(XEN)    [<00000a0000274b7c>] arch_do_domctl+0x48/0x328

Fixes: 4c733873b5c2 ("xen/arm: Add XEN_DOMCTL_dt_overlay and device attachment 
to domains")
Signed-off-by: Michal Orzel <michal.orzel@xxxxxxx>
Reviewed-by: Stefano Stabellini <sstabellini@xxxxxxxxxx>
---
Changes in v2:
 - Add Rb
---
 xen/common/dt-overlay.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/xen/common/dt-overlay.c b/xen/common/dt-overlay.c
index d53b4706cd2f..8606b14d1e8e 100644
--- a/xen/common/dt-overlay.c
+++ b/xen/common/dt-overlay.c
@@ -908,8 +908,11 @@ static long handle_attach_overlay_nodes(struct domain *d,
  out:
     spin_unlock(&overlay_lock);
 
-    rangeset_destroy(entry->irq_ranges);
-    rangeset_destroy(entry->iomem_ranges);
+    if ( entry )
+    {
+        rangeset_destroy(entry->irq_ranges);
+        rangeset_destroy(entry->iomem_ranges);
+    }
 
     return rc;
 }
-- 
2.25.1




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.