[PATCH] KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing

Vincent Donnefort vdonnefort at google.com
Wed Jul 8 00:43:44 PDT 2026


On Tue, Jul 07, 2026 at 07:32:44PM +0100, Fuad Tabba wrote:
> Hi Vincent,
> 
> On Tue, 7 Jul 2026 at 17:50, Vincent Donnefort <vdonnefort at google.com> wrote:
> >
> > In the very unlikely event of a failure in __map_hyp, the allocated
> > backing pages are leaked in hyp_trace_buffer_alloc_bpages_backing(). Fix
> > this by freeing the pages on error.
> >
> > Fixes: 3aed038aac8d ("KVM: arm64: Add trace remote for the nVHE/pKVM hyp")
> > Reported-by: Sashiko <sashiko-bot at kernel.org>
> > Signed-off-by: Vincent Donnefort <vdonnefort at google.com>
> >
> > diff --git a/arch/arm64/kvm/hyp_trace.c b/arch/arm64/kvm/hyp_trace.c
> > index 2411b4c32932..5fbbfd40376f 100644
> > --- a/arch/arm64/kvm/hyp_trace.c
> > +++ b/arch/arm64/kvm/hyp_trace.c
> > @@ -160,6 +160,7 @@ static int hyp_trace_buffer_alloc_bpages_backing(struct hyp_trace_buffer *trace_
> >         int nr_bpages = (PAGE_ALIGN(size) / PAGE_SIZE) + 1;
> >         size_t backing_size;
> >         void *start;
> > +       int ret;
> >
> >         backing_size = PAGE_ALIGN(sizeof(struct simple_buffer_page) * nr_bpages *
> >                                   num_possible_cpus());
> > @@ -171,7 +172,11 @@ static int hyp_trace_buffer_alloc_bpages_backing(struct hyp_trace_buffer *trace_
> >         trace_buffer->desc->bpages_backing_start = (unsigned long)start;
> >         trace_buffer->desc->bpages_backing_size = backing_size;
> >
> > -       return __map_hyp(start, backing_size);
> > +       ret = __map_hyp(start, backing_size);
> > +       if (ret)
> > +               free_pages_exact(start, backing_size);
> > +
> > +       return ret;
> >  }
> 
> nit: would be a bit cleaner to do move the desc assignment to after
> the check. Also, I think sashiko found another real bug, don't think
> it's serious but worth fixing.

Ha yes good point.

For the other bug, I saw it but that will be for the tracing ML

> 
> That said...
> 
> Reviewed-by: Fuad Tabba <fuad.tabba at linux.dev>
> Tested-by: Fuad Tabba < fuad.tabba at linux.dev>

Thanks

> 
> Cheers,
> /fuad
> 
> >
> >  static void hyp_trace_buffer_free_bpages_backing(struct hyp_trace_buffer *trace_buffer)
> >
> > base-commit: 8cdeaa50eae8dad34885515f62559ee83e7e8dda
> > --
> > 2.55.0.rc2.803.g1fd1e6609c-goog
> >



More information about the linux-arm-kernel mailing list