KVM: PPC: Book3S: Suppress warnings when allocating too big memory slots
authorAlexey Kardashevskiy <aik@ozlabs.ru>
Wed, 1 Sep 2021 08:45:12 +0000 (18:45 +1000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 27 Jan 2022 09:54:22 +0000 (10:54 +0100)
[ Upstream commit 511d25d6b789fffcb20a3eb71899cf974a31bd9d ]

The userspace can trigger "vmalloc size %lu allocation failure: exceeds
total pages" via the KVM_SET_USER_MEMORY_REGION ioctl.

This silences the warning by checking the limit before calling vzalloc()
and returns ENOMEM if failed.

This does not call underlying valloc helpers as __vmalloc_node() is only
exported when CONFIG_TEST_VMALLOC_MODULE and __vmalloc_node_range() is
not exported at all.

Spotted by syzkaller.

Signed-off-by: Alexey Kardashevskiy <aik@ozlabs.ru>
[mpe: Use 'size' for the variable rather than 'cb']
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://lore.kernel.org/r/20210901084512.1658628-1-aik@ozlabs.ru
Signed-off-by: Sasha Levin <sashal@kernel.org>
arch/powerpc/kvm/book3s_hv.c

index 175967a195c4459075cdb7cc3c70841a64a7a4cc..527c205d5a5f5f4f05d7416ef83ede53d5479d23 100644 (file)
@@ -4557,8 +4557,12 @@ static int kvmppc_core_prepare_memory_region_hv(struct kvm *kvm,
        unsigned long npages = mem->memory_size >> PAGE_SHIFT;
 
        if (change == KVM_MR_CREATE) {
-               slot->arch.rmap = vzalloc(array_size(npages,
-                                         sizeof(*slot->arch.rmap)));
+               unsigned long size = array_size(npages, sizeof(*slot->arch.rmap));
+
+               if ((size >> PAGE_SHIFT) > totalram_pages())
+                       return -ENOMEM;
+
+               slot->arch.rmap = vzalloc(size);
                if (!slot->arch.rmap)
                        return -ENOMEM;
        }