Skip to content

Commit 966d47e

Browse files
Anton Gusevardbiesheuvel
authored andcommitted
efi: fix potential NULL deref in efi_mem_reserve_persistent
When iterating on a linked list, a result of memremap is dereferenced without checking it for NULL. This patch adds a check that falls back on allocating a new page in case memremap doesn't succeed. Found by Linux Verification Center (linuxtesting.org) with SVACE. Fixes: 18df757 ("efi/memreserve: deal with memreserve entries in unmapped memory") Signed-off-by: Anton Gusev <[email protected]> [ardb: return -ENOMEM instead of breaking out of the loop] Signed-off-by: Ard Biesheuvel <[email protected]>
1 parent 636ab41 commit 966d47e

File tree

1 file changed

+2
-0
lines changed
  • drivers/firmware/efi

1 file changed

+2
-0
lines changed

drivers/firmware/efi/efi.c

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1007,6 +1007,8 @@ int __ref efi_mem_reserve_persistent(phys_addr_t addr, u64 size)
10071007
/* first try to find a slot in an existing linked list entry */
10081008
for (prsv = efi_memreserve_root->next; prsv; ) {
10091009
rsv = memremap(prsv, sizeof(*rsv), MEMREMAP_WB);
1010+
if (!rsv)
1011+
return -ENOMEM;
10101012
index = atomic_fetch_add_unless(&rsv->count, 1, rsv->size);
10111013
if (index < rsv->size) {
10121014
rsv->entry[index].base = addr;

0 commit comments

Comments
 (0)