Wei Yongjun
fa2e0d4e4a
kernel/relay.c: fix memleak on destroy relay channel
commit 71e843295c680898959b22dc877ae3839cc22470 upstream.
kmemleak report memory leak as follows:
unreferenced object 0x607ee4e5f948 (size 8):
comm "syz-executor.1", pid 2098, jiffies 4295031601 (age 288.468s)
hex dump (first 8 bytes):
00 00 00 00 00 00 00 00 ........
backtrace:
relay_open kernel/relay.c:583 [inline]
relay_open+0xb6/0x970 kernel/relay.c:563
do_blk_trace_setup+0x4a8/0xb20 kernel/trace/blktrace.c:557
__blk_trace_setup+0xb6/0x150 kernel/trace/blktrace.c:597
blk_trace_ioctl+0x146/0x280 kernel/trace/blktrace.c:738
blkdev_ioctl+0xb2/0x6a0 block/ioctl.c:613
block_ioctl+0xe5/0x120 fs/block_dev.c:1871
vfs_ioctl fs/ioctl.c:48 [inline]
__do_sys_ioctl fs/ioctl.c:753 [inline]
__se_sys_ioctl fs/ioctl.c:739 [inline]
__x64_sys_ioctl+0x170/0x1ce fs/ioctl.c:739
do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x44/0xa9
'chan->buf' is malloced in relay_open() by alloc_percpu() but not free
while destroy the relay channel. Fix it by adding free_percpu() before
return from relay_destroy_channel().
Fixes: 017c59c042 ("relay: Use per CPU constructs for the relay channel buffer pointers")
Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Wei Yongjun <weiyongjun1@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: David Rientjes <rientjes@google.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Daniel Axtens <dja@axtens.net>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Akash Goel <akash.goel@intel.com>
Cc: <stable@vger.kernel.org>
Link: http://lkml.kernel.org/r/20200817122826.48518-1-weiyongjun1@huawei.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2020-08-26 10:40:51 +02:00 |
| .. |
|
bpf
|
bpf: sockmap: Require attach_bpf_fd when detaching a program
|
2020-08-07 09:34:02 +02:00 |
|
cgroup
|
cgroup: fix cgroup_sk_alloc() for sk_clone_lock()
|
2020-07-22 09:32:49 +02:00 |
|
configs
|
|
|
|
debug
|
kgdb: Avoid suspicious RCU usage warning
|
2020-07-09 09:37:51 +02:00 |
|
dma
|
dma-direct: fix data truncation in dma_direct_get_required_mask()
|
2020-04-29 16:33:00 +02:00 |
|
events
|
perf/core: Fix endless multiplex timer
|
2020-08-11 15:33:32 +02:00 |
|
gcov
|
kernel/gcov/fs.c: gcov_seq_next() should increase position index
|
2020-04-29 16:33:00 +02:00 |
|
irq
|
genirq/PM: Always unlock IRQ descriptor in rearm_wake_irq()
|
2020-08-21 13:05:20 +02:00 |
|
livepatch
|
livepatch: Nullify obj->mod in klp_module_coming()'s error path
|
2019-08-19 13:03:37 +02:00 |
|
locking
|
locktorture: Print ratio of acquisitions, not failures
|
2020-04-23 10:36:44 +02:00 |
|
power
|
PM: hibernate: Freeze kernel threads in software_resume()
|
2020-05-06 08:15:09 +02:00 |
|
printk
|
printk: queue wake_up_klogd irq_work only if per-CPU areas are ready
|
2020-05-02 08:48:42 +02:00 |
|
rcu
|
rcu: Allow only one expedited GP to run concurrently with wakeups
|
2020-03-05 16:43:50 +01:00 |
|
sched
|
sched/uclamp: Fix initialization of struct uclamp_rq
|
2020-08-19 08:15:55 +02:00 |
|
time
|
random32: update the net random state on interrupt and activity
|
2020-08-07 09:34:01 +02:00 |
|
trace
|
tracing: Move pipe reference to trace array instead of current_tracer
|
2020-08-21 13:05:27 +02:00 |
|
.gitignore
|
|
|
|
acct.c
|
|
|
|
async.c
|
|
|
|
audit.c
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
audit.h
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
audit_fsnotify.c
|
|
|
|
audit_tree.c
|
|
|
|
audit_watch.c
|
audit_get_nd(): don't unlock parent too early
|
2019-11-10 11:56:55 -05:00 |
|
auditfilter.c
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
auditsc.c
|
|
|
|
backtracetest.c
|
|
|
|
bounds.c
|
|
|
|
capability.c
|
|
|
|
compat.c
|
|
|
|
configs.c
|
kernel/configs: Replace GPL boilerplate code with SPDX identifier
|
2019-07-30 18:34:15 +02:00 |
|
context_tracking.c
|
|
|
|
cpu.c
|
sched/core: Fix illegal RCU from offline CPUs
|
2020-06-22 09:31:01 +02:00 |
|
cpu_pm.c
|
kernel/cpu_pm: Fix uninitted local in cpu_pm
|
2020-06-22 09:31:22 +02:00 |
|
crash_core.c
|
|
|
|
crash_dump.c
|
|
|
|
cred.c
|
keys: Fix request_key() cache
|
2020-01-17 19:48:42 +01:00 |
|
delayacct.c
|
|
|
|
dma.c
|
|
|
|
elfcore.c
|
kernel/elfcore.c: include proper prototypes
|
2019-09-25 17:51:39 -07:00 |
|
exec_domain.c
|
|
|
|
exit.c
|
exit: Move preemption fixup up, move blocking operations down
|
2020-06-22 09:31:01 +02:00 |
|
extable.c
|
extable: Add function to search only kernel exception table
|
2019-08-21 22:23:48 +10:00 |
|
fail_function.c
|
|
|
|
fork.c
|
fork: prevent accidental access to clone3 features
|
2020-05-20 08:20:22 +02:00 |
|
freezer.c
|
Revert "libata, freezer: avoid block device removal while system is frozen"
|
2019-10-06 09:11:37 -06:00 |
|
futex.c
|
futex: Unbreak futex hashing
|
2020-03-25 08:25:58 +01:00 |
|
gen_kheaders.sh
|
kheaders: substituting --sort in archive creation
|
2019-10-17 09:08:19 +09:00 |
|
groups.c
|
|
|
|
hung_task.c
|
|
|
|
iomem.c
|
mm/nvdimm: add is_ioremap_addr and use that to check ioremap address
|
2019-07-12 11:05:40 -07:00 |
|
irq_work.c
|
|
|
|
jump_label.c
|
jump_label: Don't warn on __exit jump entries
|
2019-08-29 15:10:10 +01:00 |
|
kallsyms.c
|
kallsyms: Refactor kallsyms_show_value() to take cred
|
2020-07-16 08:16:44 +02:00 |
|
kcmp.c
|
|
|
|
Kconfig.freezer
|
|
|
|
Kconfig.hz
|
|
|
|
Kconfig.locks
|
|
|
|
Kconfig.preempt
|
sched/rt, Kconfig: Unbreak def/oldconfig with CONFIG_PREEMPT=y
|
2019-07-22 18:05:11 +02:00 |
|
kcov.c
|
|
|
|
kexec.c
|
kexec_load: Disable at runtime if the kernel is locked down
|
2019-08-19 21:54:15 -07:00 |
|
kexec_core.c
|
kexec: bail out upon SIGKILL when allocating memory.
|
2019-09-25 17:51:40 -07:00 |
|
kexec_elf.c
|
kexec_elf: support 32 bit ELF files
|
2019-09-06 23:58:44 +02:00 |
|
kexec_file.c
|
Merge branch 'next-lockdown' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
|
2019-09-28 08:14:15 -07:00 |
|
kexec_internal.h
|
|
|
|
kheaders.c
|
|
|
|
kmod.c
|
kmod: make request_module() return an error when autoloading is disabled
|
2020-04-17 10:50:22 +02:00 |
|
kprobes.c
|
kprobes: Fix NULL pointer dereference at kprobe_ftrace_handler
|
2020-08-21 13:05:27 +02:00 |
|
ksysfs.c
|
|
|
|
kthread.c
|
kthread: make __kthread_queue_delayed_work static
|
2019-10-16 09:20:58 -07:00 |
|
latencytop.c
|
|
|
|
Makefile
|
Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity
|
2019-09-27 19:37:27 -07:00 |
|
module-internal.h
|
|
|
|
module.c
|
module: Correctly truncate sysfs sections output
|
2020-08-21 13:05:28 +02:00 |
|
module_signature.c
|
MODSIGN: Export module signature definitions
|
2019-08-05 18:39:56 -04:00 |
|
module_signing.c
|
MODSIGN: Export module signature definitions
|
2019-08-05 18:39:56 -04:00 |
|
notifier.c
|
x86/mm: split vmalloc_sync_all()
|
2020-03-25 08:25:58 +01:00 |
|
nsproxy.c
|
|
|
|
padata.c
|
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
|
2020-06-17 16:40:22 +02:00 |
|
panic.c
|
panic: ensure preemption is disabled during panic()
|
2019-10-07 15:47:19 -07:00 |
|
params.c
|
lockdown: Lock down module params that specify hardware parameters (eg. ioport)
|
2019-08-19 21:54:16 -07:00 |
|
pid.c
|
kernel/pid.c: convert struct pid count to refcount_t
|
2019-07-16 19:23:24 -07:00 |
|
pid_namespace.c
|
proc/sysctl: add shared variables for range check
|
2019-07-18 17:08:07 -07:00 |
|
profile.c
|
|
|
|
ptrace.c
|
ptrace: reintroduce usage of subjective credentials in ptrace_has_cap()
|
2020-01-23 08:22:36 +01:00 |
|
range.c
|
|
|
|
reboot.c
|
|
|
|
relay.c
|
kernel/relay.c: fix memleak on destroy relay channel
|
2020-08-26 10:40:51 +02:00 |
|
resource.c
|
/dev/mem: Revoke mappings when a driver claims the region
|
2020-06-24 17:50:35 +02:00 |
|
rseq.c
|
|
|
|
seccomp.c
|
seccomp: Fix ioctl number for SECCOMP_IOCTL_NOTIF_ID_VALID
|
2020-08-19 08:15:58 +02:00 |
|
signal.c
|
signal: check sig before setting info in kill_pid_usb_asyncio
|
2020-05-02 08:48:55 +02:00 |
|
smp.c
|
smp: Warn on function calls from softirq context
|
2019-07-20 11:27:16 +02:00 |
|
smpboot.c
|
|
|
|
smpboot.h
|
|
|
|
softirq.c
|
|
|
|
stackleak.c
|
|
|
|
stacktrace.c
|
stacktrace: Don't skip first entry on noncurrent tasks
|
2019-11-04 21:19:25 +01:00 |
|
stop_machine.c
|
stop_machine: Avoid potential race behaviour
|
2019-10-17 12:47:12 +02:00 |
|
sys.c
|
Merge branch 'timers-core-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
|
2019-09-17 12:35:15 -07:00 |
|
sys_ni.c
|
|
|
|
sysctl.c
|
kernel: sysctl: make drop_caches write-only
|
2020-01-04 19:18:32 +01:00 |
|
sysctl_binary.c
|
|
|
|
task_work.c
|
|
|
|
taskstats.c
|
taskstats: fix data-race
|
2020-01-09 10:19:54 +01:00 |
|
test_kprobes.c
|
|
|
|
torture.c
|
torture: Remove exporting of internal functions
|
2019-08-01 14:30:22 -07:00 |
|
tracepoint.c
|
The main changes in this release include:
|
2019-07-18 11:51:00 -07:00 |
|
tsacct.c
|
|
|
|
ucount.c
|
proc/sysctl: add shared variables for range check
|
2019-07-18 17:08:07 -07:00 |
|
uid16.c
|
|
|
|
uid16.h
|
|
|
|
umh.c
|
umh: fix memory leak on execve failure
|
2020-05-20 08:20:13 +02:00 |
|
up.c
|
|
|
|
user-return-notifier.c
|
|
|
|
user.c
|
|
|
|
user_namespace.c
|
|
|
|
utsname.c
|
|
|
|
utsname_sysctl.c
|
|
|
|
watchdog.c
|
watchdog/softlockup: Enforce that timestamp is valid on boot
|
2020-02-24 08:36:52 +01:00 |
|
watchdog_hld.c
|
|
|
|
workqueue.c
|
workqueue: don't use wq_select_unbound_cpu() for bound works
|
2020-03-18 07:17:50 +01:00 |
|
workqueue_internal.h
|
|
|