]> www.infradead.org Git - users/dwmw2/linux.git/commitdiff
libbpf: Fix realloc usage in bpf_core_find_cands
authorAndrii Nakryiko <andriin@fb.com>
Fri, 24 Jan 2020 20:18:46 +0000 (12:18 -0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 11 Feb 2020 12:36:59 +0000 (04:36 -0800)
commit 35b9211c0a2427e8f39e534f442f43804fc8d5ca upstream.

Fix bug requesting invalid size of reallocated array when constructing CO-RE
relocation candidate list. This can cause problems if there are many potential
candidates and a very fine-grained memory allocator bucket sizes are used.

Fixes: ddc7c3042614 ("libbpf: implement BPF CO-RE offset relocation algorithm")
Reported-by: William Smith <williampsmith@fb.com>
Signed-off-by: Andrii Nakryiko <andriin@fb.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Yonghong Song <yhs@fb.com>
Link: https://lore.kernel.org/bpf/20200124201847.212528-1-andriin@fb.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
tools/lib/bpf/libbpf.c

index 41158d383d91f69748b984f768b44048ec4307a4..f976ed354990c274c485ef8761fb36702992f07b 100644 (file)
@@ -2744,7 +2744,9 @@ static struct ids_vec *bpf_core_find_cands(const struct btf *local_btf,
                if (strncmp(local_name, targ_name, local_essent_len) == 0) {
                        pr_debug("[%d] %s: found candidate [%d] %s\n",
                                 local_type_id, local_name, i, targ_name);
-                       new_ids = realloc(cand_ids->data, cand_ids->len + 1);
+                       new_ids = reallocarray(cand_ids->data,
+                                              cand_ids->len + 1,
+                                              sizeof(*cand_ids->data));
                        if (!new_ids) {
                                err = -ENOMEM;
                                goto err_out;