KVM: PPC: fix information leak to userland
Structure kvm_ppc_pvinfo is copied to userland with flags and pad fields unitialized. It leads to leaking of contents of kernel stack memory. Signed-off-by: Vasiliy Kulikov <segooon@gmail.com> Signed-off-by: Marcelo Tosatti <mtosatti@redhat.com>
This commit is contained in:
parent
eb45fda45f
commit
d8cdddcd64
|
@ -617,6 +617,7 @@ long kvm_arch_vm_ioctl(struct file *filp,
|
||||||
switch (ioctl) {
|
switch (ioctl) {
|
||||||
case KVM_PPC_GET_PVINFO: {
|
case KVM_PPC_GET_PVINFO: {
|
||||||
struct kvm_ppc_pvinfo pvinfo;
|
struct kvm_ppc_pvinfo pvinfo;
|
||||||
|
memset(&pvinfo, 0, sizeof(pvinfo));
|
||||||
r = kvm_vm_ioctl_get_pvinfo(&pvinfo);
|
r = kvm_vm_ioctl_get_pvinfo(&pvinfo);
|
||||||
if (copy_to_user(argp, &pvinfo, sizeof(pvinfo))) {
|
if (copy_to_user(argp, &pvinfo, sizeof(pvinfo))) {
|
||||||
r = -EFAULT;
|
r = -EFAULT;
|
||||||
|
|
Loading…
Reference in New Issue