diff mbox series

[AUTOSEL,4.18,32/59] block: Clear kernel memory before copying to user

Message ID 20181114222335.99339-32-sashal@kernel.org (mailing list archive)
State New, archived
Headers show
Series None | expand

Commit Message

Sasha Levin Nov. 14, 2018, 10:23 p.m. UTC
From: Keith Busch <keith.busch@intel.com>

[ Upstream commit f3587d76da05f68098ddb1cb3c98cc6a9e8a402c ]

If the kernel allocates a bounce buffer for user read data, this memory
needs to be cleared before copying it to the user, otherwise it may leak
kernel memory to user space.

Laurence Oberman <loberman@redhat.com>
Signed-off-by: Keith Busch <keith.busch@intel.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 block/bio.c | 1 +
 1 file changed, 1 insertion(+)
diff mbox series

Patch

diff --git a/block/bio.c b/block/bio.c
index ff94640bc734..5ad106e765fc 100644
--- a/block/bio.c
+++ b/block/bio.c
@@ -1336,6 +1336,7 @@  struct bio *bio_copy_user_iov(struct request_queue *q,
 		if (ret)
 			goto cleanup;
 	} else {
+		zero_fill_bio(bio);
 		iov_iter_advance(iter, bio->bi_iter.bi_size);
 	}