diff options
| author | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2026-04-30 12:13:53 +0300 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2026-04-30 12:13:53 +0300 |
| commit | b74b62f806b6112138e89ea7d5616dac7c089cfa (patch) | |
| tree | c7f2de486d824c57956902e7ac3ffa70599308fa | |
| parent | 735d394779c92a6f31bf050233082d6e09355b09 (diff) | |
| parent | 1fe06068166d4fc16722201f267b1fe19efad639 (diff) | |
| download | linux-rolling-lts.tar.xz | |
Merge v6.18.26linux-rolling-lts
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
| -rw-r--r-- | Makefile | 2 | ||||
| -rw-r--r-- | drivers/xen/privcmd.c | 7 | ||||
| -rw-r--r-- | drivers/xen/sys-hypervisor.c | 8 |
3 files changed, 14 insertions, 3 deletions
@@ -1,7 +1,7 @@ # SPDX-License-Identifier: GPL-2.0 VERSION = 6 PATCHLEVEL = 18 -SUBLEVEL = 25 +SUBLEVEL = 26 EXTRAVERSION = NAME = Baby Opossum Posse diff --git a/drivers/xen/privcmd.c b/drivers/xen/privcmd.c index cbc62f0df11b..f37d8d212c06 100644 --- a/drivers/xen/privcmd.c +++ b/drivers/xen/privcmd.c @@ -1619,6 +1619,12 @@ static void privcmd_close(struct vm_area_struct *vma) kvfree(pages); } +static int privcmd_may_split(struct vm_area_struct *area, unsigned long addr) +{ + /* Forbid splitting, avoids double free via privcmd_close(). */ + return -EINVAL; +} + static vm_fault_t privcmd_fault(struct vm_fault *vmf) { printk(KERN_DEBUG "privcmd_fault: vma=%p %lx-%lx, pgoff=%lx, uv=%p\n", @@ -1630,6 +1636,7 @@ static vm_fault_t privcmd_fault(struct vm_fault *vmf) static const struct vm_operations_struct privcmd_vm_ops = { .close = privcmd_close, + .may_split = privcmd_may_split, .fault = privcmd_fault }; diff --git a/drivers/xen/sys-hypervisor.c b/drivers/xen/sys-hypervisor.c index 2f880374b463..c1a0ca1b1b5f 100644 --- a/drivers/xen/sys-hypervisor.c +++ b/drivers/xen/sys-hypervisor.c @@ -366,6 +366,8 @@ static ssize_t buildid_show(struct hyp_sysfs_attr *attr, char *buffer) ret = sprintf(buffer, "<denied>"); return ret; } + if (ret > PAGE_SIZE) + return -ENOSPC; buildid = kmalloc(sizeof(*buildid) + ret, GFP_KERNEL); if (!buildid) @@ -373,8 +375,10 @@ static ssize_t buildid_show(struct hyp_sysfs_attr *attr, char *buffer) buildid->len = ret; ret = HYPERVISOR_xen_version(XENVER_build_id, buildid); - if (ret > 0) - ret = sprintf(buffer, "%s", buildid->buf); + if (ret > 0) { + /* Build id is binary, not a string. */ + memcpy(buffer, buildid->buf, ret); + } kfree(buildid); return ret; |
