diff options
| author | Juergen Gross <jgross@suse.com> | 2022-02-25 16:05:42 +0100 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2022-03-11 10:15:13 +0100 |
| commit | fbc57368ea527dcfa909908fc47a851a56e4e5ce (patch) | |
| tree | 84bfa7533b638b98deca7cfb9ee176566d302091 /include/xen | |
| parent | 62a696c15cfcfd32527f81ca3d94f2bde57475dc (diff) | |
xen/gntalloc: don't use gnttab_query_foreign_access()
Commit d3b6372c5881cb54925212abb62c521df8ba4809 upstream.
Using gnttab_query_foreign_access() is unsafe, as it is racy by design.
The use case in the gntalloc driver is not needed at all. While at it
replace the call of gnttab_end_foreign_access_ref() with a call of
gnttab_end_foreign_access(), which is what is really wanted there. In
case the grant wasn't used due to an allocation failure, just free the
grant via gnttab_free_grant_reference().
This is CVE-2022-23039 / part of XSA-396.
Reported-by: Demi Marie Obenour <demi@invisiblethingslab.com>
Signed-off-by: Juergen Gross <jgross@suse.com>
Reviewed-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'include/xen')
0 files changed, 0 insertions, 0 deletions
