summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorClaudio Imbrenda <imbrenda@linux.ibm.com>2026-08-12 12:44:28 +0200
committerClaudio Imbrenda <imbrenda@linux.ibm.com>2026-08-12 13:43:35 +0200
commit88e22ffd1e46b95e40a6afabe486deb1d31a3ae1 (patch)
tree9ce4616c1eebfecbc21f5e7cbaf3a37112340aca
parentc44d36d8e6501c4934412d9014e5e02da9efdb8f (diff)
downloadlinux-stable-88e22ffd1e46b95e40a6afabe486deb1d31a3ae1.tar.gz
linux-stable-88e22ffd1e46b95e40a6afabe486deb1d31a3ae1.zip
KVM: s390: Properly handle NULL pointer in dat_cond_set_storage_key()
Some callers pass NULL as oldkey. Calling page_cond_set_storage_key() will cause that NULL pointer to get dereferenced. Fix by checking for NULL and assigning the pointer to a dummy local variable to avoid crashes. Fixes: 8e03e8316eb2 ("KVM: s390: KVM page table management functions: storage keys") Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com> Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com> Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com> Message-ID: <20260812104436.109741-2-imbrenda@linux.ibm.com>
-rw-r--r--arch/s390/kvm/dat.c5
1 files changed, 4 insertions, 1 deletions
diff --git a/arch/s390/kvm/dat.c b/arch/s390/kvm/dat.c
index 3f2d6e8902d7..165c704fcf29 100644
--- a/arch/s390/kvm/dat.c
+++ b/arch/s390/kvm/dat.c
@@ -722,9 +722,12 @@ int dat_cond_set_storage_key(struct kvm_s390_mmu_cache *mmc, union asce asce, gf
if (rc)
return rc;
- if (!ptep)
+ if (!ptep) {
+ if (!oldkey)
+ oldkey = &prev;
return page_cond_set_storage_key(large_crste_to_phys(*crstep, gfn), skey, oldkey,
nq, mr, mc);
+ }
old = pgste_get_lock(ptep);
pgste = old;