It is possible to trigger use after free during HPT resize
causing host kernel to crash. More details and analysis of
the problem can be found in change with corresponding subject
(KVM: PPC: Book3S HV: Fix use after free in case of multiple
resize requests).

We need some changes to prepare for the fix, especially
make ->error in HPT resize instance single point for
tracking allocation state.

See individual commit description message to get more
information on changes presented.

v2:
 Serhii Popovych: Tested with current 4.15-rc2 as host kernel on P8
                  with same testcase as for v1: no problems so far.

Serhii Popovych (2):
  KVM: PPC: Book3S HV: Drop prepare_done from struct kvm_resize_hpt and
    cleanups
  KVM: PPC: Book3S HV: Fix use after free in case of multiple resize
    requests

 arch/powerpc/kvm/book3s_64_mmu_hv.c | 84 +++++++++++++++++++++++++------------
 1 file changed, 57 insertions(+), 27 deletions(-)

-- 
1.8.3.1

Reply via email to