| From 17c98e829d25c87c26578f7c68747e0f83fd9c85 Mon Sep 17 00:00:00 2001 |
| From: Andrii Nakryiko <andriin@fb.com> |
| Date: Wed, 6 Nov 2019 18:08:51 -0800 |
| Subject: [PATCH] libbpf: Fix memory leak/double free issue |
| |
| commit 3dc5e059821376974177cc801d377e3fcdac6712 upstream. |
| |
| Coverity scan against Github libbpf code found the issue of not freeing memory and |
| leaving already freed memory still referenced from bpf_program. Fix it by |
| re-assigning successfully reallocated memory sooner. |
| |
| Fixes: 2993e0515bb4 ("tools/bpf: add support to read .BTF.ext sections") |
| Signed-off-by: Andrii Nakryiko <andriin@fb.com> |
| Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> |
| Link: https://lore.kernel.org/bpf/20191107020855.3834758-2-andriin@fb.com |
| Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com> |
| |
| diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c |
| index 88d506951b07..774aa4f546c5 100644 |
| --- a/tools/lib/bpf/libbpf.c |
| +++ b/tools/lib/bpf/libbpf.c |
| @@ -1924,6 +1924,7 @@ bpf_program__reloc_text(struct bpf_program *prog, struct bpf_object *obj, |
| pr_warning("oom in prog realloc\n"); |
| return -ENOMEM; |
| } |
| + prog->insns = new_insn; |
| |
| if (obj->btf_ext) { |
| err = bpf_program_reloc_btf_ext(prog, obj, |
| @@ -1935,7 +1936,6 @@ bpf_program__reloc_text(struct bpf_program *prog, struct bpf_object *obj, |
| |
| memcpy(new_insn + prog->insns_cnt, text->insns, |
| text->insns_cnt * sizeof(*insn)); |
| - prog->insns = new_insn; |
| prog->main_prog_cnt = prog->insns_cnt; |
| prog->insns_cnt = new_cnt; |
| pr_debug("added %zd insn from %s to prog %s\n", |
| -- |
| 2.7.4 |
| |