| From dd0c5422c6564b7c96744f5648bd64477ffce391 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Thu, 4 Feb 2021 09:49:50 -0800 |
| Subject: ima: Free IMA measurement buffer on error |
| |
| From: Lakshmi Ramasubramanian <nramas@linux.microsoft.com> |
| |
| [ Upstream commit 6d14c6517885fa68524238787420511b87d671df ] |
| |
| IMA allocates kernel virtual memory to carry forward the measurement |
| list, from the current kernel to the next kernel on kexec system call, |
| in ima_add_kexec_buffer() function. In error code paths this memory |
| is not freed resulting in memory leak. |
| |
| Free the memory allocated for the IMA measurement list in |
| the error code paths in ima_add_kexec_buffer() function. |
| |
| Signed-off-by: Lakshmi Ramasubramanian <nramas@linux.microsoft.com> |
| Suggested-by: Tyler Hicks <tyhicks@linux.microsoft.com> |
| Fixes: 7b8589cc29e7 ("ima: on soft reboot, save the measurement list") |
| Signed-off-by: Mimi Zohar <zohar@linux.ibm.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| security/integrity/ima/ima_kexec.c | 1 + |
| 1 file changed, 1 insertion(+) |
| |
| diff --git a/security/integrity/ima/ima_kexec.c b/security/integrity/ima/ima_kexec.c |
| index 16bd18747cfa0..9f8449dea5b69 100644 |
| --- a/security/integrity/ima/ima_kexec.c |
| +++ b/security/integrity/ima/ima_kexec.c |
| @@ -124,6 +124,7 @@ void ima_add_kexec_buffer(struct kimage *image) |
| ret = kexec_add_buffer(&kbuf); |
| if (ret) { |
| pr_err("Error passing over kexec measurement buffer.\n"); |
| + vfree(kexec_buffer); |
| return; |
| } |
| |
| -- |
| 2.27.0 |
| |