lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:	Sat, 27 Jun 2009 01:29:37 +0300
From:	Sergey Senozhatsky <sergey.senozhatsky@...l.by>
To:	Greg KH <gregkh@...e.de>
Cc:	Kay Sievers <kay.sievers@...y.org>,
	"Eric W. Biederman" <ebiederm@...ssion.com>,
	linux-kernel@...r.kernel.org
Subject: Re: [PATCH] kobject_set_name_vargs memory leak

On (06/26/09 07:49), Greg KH wrote:
> Date: Fri, 26 Jun 2009 07:49:49 -0700
> From: Greg KH <gregkh@...e.de>
> To: Sergey Senozhatsky <sergey.senozhatsky@...l.by>
> Cc: Kay Sievers <kay.sievers@...y.org>,
> 	"Eric W. Biederman" <ebiederm@...ssion.com>,
> 	linux-kernel@...r.kernel.org
> Subject: Re: [PATCH] kobject_set_name_vargs memory leak
> User-Agent: Mutt/1.5.19 (2009-01-05)
> 
> On Fri, Jun 26, 2009 at 05:36:52PM +0300, Sergey Senozhatsky wrote:
> > Hello.
> > I suppose this patch fixes memory leak in kobject.c
> > Correct me if I'm wrong.
> > Thanks.
> > -----------
> > 
> > Fix memory leak when kobject_set_name_vargs returns -ENOMEM.
> > 
> > Signed-off-by: Sergey Senozhatsky <sergey.senozhatsky@...l.by>
> > ---
> > diff --git a/lib/kobject.c b/lib/kobject.c
> > index b512b74..922cd8c 100644
> > --- a/lib/kobject.c
> > +++ b/lib/kobject.c
> > @@ -222,8 +222,10 @@ int kobject_set_name_vargs(struct kobject *kobj, const char *fmt,
> >  		return 0;
> >  
> >  	kobj->name = kvasprintf(GFP_KERNEL, fmt, vargs);
> > -	if (!kobj->name)
> > +	if (!kobj->name) {
> > +		kfree(old_name);
> >  		return -ENOMEM;
> > +	}
> 
> We've been through this before (search lkml archives).  If kvasprintf
> fails, then we don't want to free old_name, as the caller might want to
> do something with it.
> 
Hello Greg,

int kobject_set_name_vargs.... {
	const char *old_name = kobj->name;

old_name is local variable.

In the following lines we overwrite kobject->name.

	kobj->name = kvasprintf(GFP_KERNEL, fmt, vargs);
	if (!kobj->name)
		return -ENOMEM;

It's not clear to me how we can do anything (including kfree) with old_name after 'return -ENOMEM'.

Well, I'll try to search lklm.
Thanks.


> Or something along those lines, I can't remember the exact reasoning
> this early in the morning.
> 
> Kay, do you remember?
> 
> thanks,
> 
> greg k-h
> 

	Sergey
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ