[PATCH] KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing
Vincent Donnefort
vdonnefort at google.com
Wed Jul 8 00:43:44 PDT 2026
On Tue, Jul 07, 2026 at 07:32:44PM +0100, Fuad Tabba wrote:
> Hi Vincent,
>
> On Tue, 7 Jul 2026 at 17:50, Vincent Donnefort <vdonnefort at google.com> wrote:
> >
> > In the very unlikely event of a failure in __map_hyp, the allocated
> > backing pages are leaked in hyp_trace_buffer_alloc_bpages_backing(). Fix
> > this by freeing the pages on error.
> >
> > Fixes: 3aed038aac8d ("KVM: arm64: Add trace remote for the nVHE/pKVM hyp")
> > Reported-by: Sashiko <sashiko-bot at kernel.org>
> > Signed-off-by: Vincent Donnefort <vdonnefort at google.com>
> >
> > diff --git a/arch/arm64/kvm/hyp_trace.c b/arch/arm64/kvm/hyp_trace.c
> > index 2411b4c32932..5fbbfd40376f 100644
> > --- a/arch/arm64/kvm/hyp_trace.c
> > +++ b/arch/arm64/kvm/hyp_trace.c
> > @@ -160,6 +160,7 @@ static int hyp_trace_buffer_alloc_bpages_backing(struct hyp_trace_buffer *trace_
> > int nr_bpages = (PAGE_ALIGN(size) / PAGE_SIZE) + 1;
> > size_t backing_size;
> > void *start;
> > + int ret;
> >
> > backing_size = PAGE_ALIGN(sizeof(struct simple_buffer_page) * nr_bpages *
> > num_possible_cpus());
> > @@ -171,7 +172,11 @@ static int hyp_trace_buffer_alloc_bpages_backing(struct hyp_trace_buffer *trace_
> > trace_buffer->desc->bpages_backing_start = (unsigned long)start;
> > trace_buffer->desc->bpages_backing_size = backing_size;
> >
> > - return __map_hyp(start, backing_size);
> > + ret = __map_hyp(start, backing_size);
> > + if (ret)
> > + free_pages_exact(start, backing_size);
> > +
> > + return ret;
> > }
>
> nit: would be a bit cleaner to do move the desc assignment to after
> the check. Also, I think sashiko found another real bug, don't think
> it's serious but worth fixing.
Ha yes good point.
For the other bug, I saw it but that will be for the tracing ML
>
> That said...
>
> Reviewed-by: Fuad Tabba <fuad.tabba at linux.dev>
> Tested-by: Fuad Tabba < fuad.tabba at linux.dev>
Thanks
>
> Cheers,
> /fuad
>
> >
> > static void hyp_trace_buffer_free_bpages_backing(struct hyp_trace_buffer *trace_buffer)
> >
> > base-commit: 8cdeaa50eae8dad34885515f62559ee83e7e8dda
> > --
> > 2.55.0.rc2.803.g1fd1e6609c-goog
> >
More information about the linux-arm-kernel
mailing list