diff mbox series

[1/1] block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern

Message ID 20230223190935.41040-2-yuxuan.luo@canonical.com
State New
Headers show
Series CVE-2022-0494 | expand

Commit Message

Yuxuan Luo Feb. 23, 2023, 7:09 p.m. UTC
Add __GFP_ZERO flag for alloc_page in function bio_copy_kern to initialize
the buffer of a bio.

Signed-off-by: Haimin Zhang <tcs.kernel@gmail.com>
Reviewed-by: Chaitanya Kulkarni <kch@nvidia.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Link: https://lore.kernel.org/r/20220216084038.15635-1-tcs.kernel@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
(backported from commit cc8f7fe1f5eab010191aa4570f27641876fa1267)
[yuxuan.luo: only add the flag to solve the uninitialization problem]
CVE-2022-0494
Signed-off-by: Yuxuan Luo <yuxuan.luo@canonical.com>
---
 block/bio.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Thadeu Lima de Souza Cascardo March 8, 2023, 1:49 p.m. UTC | #1
Acked-by: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
diff mbox series

Patch

diff --git a/block/bio.c b/block/bio.c
index 58921797f2e63..2d23063819544 100644
--- a/block/bio.c
+++ b/block/bio.c
@@ -1541,7 +1541,7 @@  struct bio *bio_copy_kern(struct request_queue *q, void *data, unsigned int len,
 		if (bytes > len)
 			bytes = len;
 
-		page = alloc_page(q->bounce_gfp | gfp_mask);
+		page = alloc_page(q->bounce_gfp | __GFP_ZERO | gfp_mask);
 		if (!page)
 			goto cleanup;