recordmcount: Fix memory leaks in the uwrite function

stable inclusion
from stable-v4.19.284
commit 444ec005404cead222ebce2561a9451c9ee5ad89
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/ICYBVX
CVE: CVE-2023-53318

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=444ec005404cead222ebce2561a9451c9ee5ad89

--------------------------------

[ Upstream commit fa359d0685 ]

Common realloc mistake: 'file_append' nulled but not freed upon failure

Link: https://lkml.kernel.org/r/20230426010527.703093-1-zenghao@kylinos.cn

Signed-off-by: Hao Zeng <zenghao@kylinos.cn>
Suggested-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Liu Kai <liukai284@huawei.com>
This commit is contained in:
Hao Zeng
2025-09-23 14:30:17 +08:00
committed by Liu Kai
parent 21b6230229
commit 6a8312cedd
+5 -1
View File
@@ -128,6 +128,7 @@ uwrite(int const fd, void const *const buf, size_t const count)
{
size_t cnt = count;
off_t idx = 0;
void *p = NULL;
file_updated = 1;
@@ -135,7 +136,10 @@ uwrite(int const fd, void const *const buf, size_t const count)
off_t aoffset = (file_ptr + count) - file_end;
if (aoffset > file_append_size) {
file_append = realloc(file_append, aoffset);
p = realloc(file_append, aoffset);
if (!p)
free(file_append);
file_append = p;
file_append_size = aoffset;
}
if (!file_append) {