diff options
| author | Claudio Imbrenda <imbrenda@linux.ibm.com> | 2026-08-12 12:44:28 +0200 |
|---|---|---|
| committer | Claudio Imbrenda <imbrenda@linux.ibm.com> | 2026-08-12 13:43:35 +0200 |
| commit | 88e22ffd1e46b95e40a6afabe486deb1d31a3ae1 (patch) | |
| tree | 9ce4616c1eebfecbc21f5e7cbaf3a37112340aca | |
| parent | c44d36d8e6501c4934412d9014e5e02da9efdb8f (diff) | |
| download | linux-stable-88e22ffd1e46b95e40a6afabe486deb1d31a3ae1.tar.gz linux-stable-88e22ffd1e46b95e40a6afabe486deb1d31a3ae1.zip | |
KVM: s390: Properly handle NULL pointer in dat_cond_set_storage_key()
Some callers pass NULL as oldkey. Calling page_cond_set_storage_key()
will cause that NULL pointer to get dereferenced.
Fix by checking for NULL and assigning the pointer to a dummy local
variable to avoid crashes.
Fixes: 8e03e8316eb2 ("KVM: s390: KVM page table management functions: storage keys")
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260812104436.109741-2-imbrenda@linux.ibm.com>
| -rw-r--r-- | arch/s390/kvm/dat.c | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/arch/s390/kvm/dat.c b/arch/s390/kvm/dat.c index 3f2d6e8902d7..165c704fcf29 100644 --- a/arch/s390/kvm/dat.c +++ b/arch/s390/kvm/dat.c @@ -722,9 +722,12 @@ int dat_cond_set_storage_key(struct kvm_s390_mmu_cache *mmc, union asce asce, gf if (rc) return rc; - if (!ptep) + if (!ptep) { + if (!oldkey) + oldkey = &prev; return page_cond_set_storage_key(large_crste_to_phys(*crstep, gfn), skey, oldkey, nq, mr, mc); + } old = pgste_get_lock(ptep); pgste = old; |
