vp_vdpa: fix id_table array not null terminated error

Allocate one extra virtio_device_id as null terminator, otherwise
vdpa_mgmtdev_get_classes() may iterate multiple times and visit
undefined memory.

Fixes: ffbda8e9df10 ("vdpa/vp_vdpa : add vdpa tool support in vp_vdpa")
Cc: stable@vger.kernel.org
Suggested-by: Parav Pandit <parav@nvidia.com>
Signed-off-by: Angus Chen <angus.chen@jaguarmicro.com>
Signed-off-by: Xiaoguang Wang <lege.wang@jaguarmicro.com>
Message-Id: <20241105133518.1494-1-lege.wang@jaguarmicro.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Reviewed-by: Parav Pandit <parav@nvidia.com>
Acked-by: Jason Wang <jasowang@redhat.com>
This commit is contained in:
Xiaoguang Wang 2024-11-05 21:35:18 +08:00 committed by Michael S. Tsirkin
parent 97ee04feb6
commit 4e39ecadf1

View File

@ -612,7 +612,11 @@ static int vp_vdpa_probe(struct pci_dev *pdev, const struct pci_device_id *id)
goto mdev_err; goto mdev_err;
} }
mdev_id = kzalloc(sizeof(struct virtio_device_id), GFP_KERNEL); /*
* id_table should be a null terminated array, so allocate one additional
* entry here, see vdpa_mgmtdev_get_classes().
*/
mdev_id = kcalloc(2, sizeof(struct virtio_device_id), GFP_KERNEL);
if (!mdev_id) { if (!mdev_id) {
err = -ENOMEM; err = -ENOMEM;
goto mdev_id_err; goto mdev_id_err;
@ -632,8 +636,8 @@ static int vp_vdpa_probe(struct pci_dev *pdev, const struct pci_device_id *id)
goto probe_err; goto probe_err;
} }
mdev_id->device = mdev->id.device; mdev_id[0].device = mdev->id.device;
mdev_id->vendor = mdev->id.vendor; mdev_id[0].vendor = mdev->id.vendor;
mgtdev->id_table = mdev_id; mgtdev->id_table = mdev_id;
mgtdev->max_supported_vqs = vp_modern_get_num_queues(mdev); mgtdev->max_supported_vqs = vp_modern_get_num_queues(mdev);
mgtdev->supported_features = vp_modern_get_features(mdev); mgtdev->supported_features = vp_modern_get_features(mdev);