mirror of
https://gitee.com/openeuler/kernel
synced 2026-09-08 23:59:09 +08:00
recordmcount: Fix memory leaks in the uwrite function
stable inclusion
from stable-v4.19.284
commit 444ec005404cead222ebce2561a9451c9ee5ad89
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/ICYBVX
CVE: CVE-2023-53318
Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=444ec005404cead222ebce2561a9451c9ee5ad89
--------------------------------
[ Upstream commit fa359d0685 ]
Common realloc mistake: 'file_append' nulled but not freed upon failure
Link: https://lkml.kernel.org/r/20230426010527.703093-1-zenghao@kylinos.cn
Signed-off-by: Hao Zeng <zenghao@kylinos.cn>
Suggested-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Liu Kai <liukai284@huawei.com>
This commit is contained in:
@@ -128,6 +128,7 @@ uwrite(int const fd, void const *const buf, size_t const count)
|
||||
{
|
||||
size_t cnt = count;
|
||||
off_t idx = 0;
|
||||
void *p = NULL;
|
||||
|
||||
file_updated = 1;
|
||||
|
||||
@@ -135,7 +136,10 @@ uwrite(int const fd, void const *const buf, size_t const count)
|
||||
off_t aoffset = (file_ptr + count) - file_end;
|
||||
|
||||
if (aoffset > file_append_size) {
|
||||
file_append = realloc(file_append, aoffset);
|
||||
p = realloc(file_append, aoffset);
|
||||
if (!p)
|
||||
free(file_append);
|
||||
file_append = p;
|
||||
file_append_size = aoffset;
|
||||
}
|
||||
if (!file_append) {
|
||||
|
||||
Reference in New Issue
Block a user