[2/6] EFI: don't leak heap contents through XEN_EFI_get_next_variable_name
diff mbox series

Message ID 62c2afe5-4ab4-50b4-f876-9324bade6ef1@suse.com
State New
Headers show
Series
  • misc hardening and some cleanup
Related show

Commit Message

Jan Beulich Feb. 5, 2020, 1:14 p.m. UTC
Commit 1f4eb9d27d0e ("EFI: fix getting EFI variable list on some
systems") switched to using the caller provided size for the copy-out
without making sure the copied buffer is properly scrubbed.

Reported-by: Ilja Van Sprundel <ivansprundel@ioactive.com>
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Reviewed-by: George Dunlap <george.dunlap@citrix.com>

Patch
diff mbox series

--- a/xen/common/efi/runtime.c
+++ b/xen/common/efi/runtime.c
@@ -571,7 +571,7 @@  int efi_runtime_call(struct xenpf_efi_ru
             return -EINVAL;
 
         size = op->u.get_next_variable_name.size;
-        name.raw = xmalloc_bytes(size);
+        name.raw = xzalloc_bytes(size);
         if ( !name.raw )
             return -ENOMEM;
         if ( copy_from_guest(name.raw, op->u.get_next_variable_name.name,