| From 35b9211c0a2427e8f39e534f442f43804fc8d5ca Mon Sep 17 00:00:00 2001 |
| From: Andrii Nakryiko <andriin@fb.com> |
| Date: Fri, 24 Jan 2020 12:18:46 -0800 |
| Subject: libbpf: Fix realloc usage in bpf_core_find_cands |
| |
| From: Andrii Nakryiko <andriin@fb.com> |
| |
| commit 35b9211c0a2427e8f39e534f442f43804fc8d5ca upstream. |
| |
| Fix bug requesting invalid size of reallocated array when constructing CO-RE |
| relocation candidate list. This can cause problems if there are many potential |
| candidates and a very fine-grained memory allocator bucket sizes are used. |
| |
| Fixes: ddc7c3042614 ("libbpf: implement BPF CO-RE offset relocation algorithm") |
| Reported-by: William Smith <williampsmith@fb.com> |
| Signed-off-by: Andrii Nakryiko <andriin@fb.com> |
| Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> |
| Acked-by: Yonghong Song <yhs@fb.com> |
| Link: https://lore.kernel.org/bpf/20200124201847.212528-1-andriin@fb.com |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| tools/lib/bpf/libbpf.c | 4 +++- |
| 1 file changed, 3 insertions(+), 1 deletion(-) |
| |
| --- a/tools/lib/bpf/libbpf.c |
| +++ b/tools/lib/bpf/libbpf.c |
| @@ -2744,7 +2744,9 @@ static struct ids_vec *bpf_core_find_can |
| if (strncmp(local_name, targ_name, local_essent_len) == 0) { |
| pr_debug("[%d] %s: found candidate [%d] %s\n", |
| local_type_id, local_name, i, targ_name); |
| - new_ids = realloc(cand_ids->data, cand_ids->len + 1); |
| + new_ids = reallocarray(cand_ids->data, |
| + cand_ids->len + 1, |
| + sizeof(*cand_ids->data)); |
| if (!new_ids) { |
| err = -ENOMEM; |
| goto err_out; |