[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-changelog] [xen staging] xen/xsm: flask: Check xmalloc_array() return in security_sid_to_context()



commit 4a647ad128a6e8ea91e9df140708d80548bf47f7
Author:     Julien Grall <julien.grall@xxxxxxx>
AuthorDate: Fri Oct 4 17:53:26 2019 +0100
Commit:     Julien Grall <julien.grall@xxxxxxx>
CommitDate: Mon Oct 7 10:09:34 2019 +0100

    xen/xsm: flask: Check xmalloc_array() return in security_sid_to_context()
    
    xmalloc_array() may return NULL if there are memory. Rather than trying
    to deference it directly, we should check the return value first.
    
    Coverity-ID: 1381852
    Signed-off-by: Julien Grall <julien.grall@xxxxxxx>
    Acked-by: Daniel De Graaf <dgdegra@xxxxxxxxxxxxx>
    Release-acked-by: Juergen Gross <jgross@xxxxxxxx>
---
 xen/xsm/flask/ss/services.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/xen/xsm/flask/ss/services.c b/xen/xsm/flask/ss/services.c
index b59928ea8a..42686535f2 100644
--- a/xen/xsm/flask/ss/services.c
+++ b/xen/xsm/flask/ss/services.c
@@ -775,6 +775,8 @@ int security_sid_to_context(u32 sid, char **scontext, u32 
*scontext_len)
 
             *scontext_len = strlen(initial_sid_to_string[sid]) + 1;
             scontextp = xmalloc_array(char, *scontext_len);
+            if ( !scontextp )
+                return -ENOMEM;
             strlcpy(scontextp, initial_sid_to_string[sid], *scontext_len);
             *scontext = scontextp;
             goto out;
--
generated by git-patchbot for /home/xen/git/xen.git#staging

_______________________________________________
Xen-changelog mailing list
Xen-changelog@xxxxxxxxxxxxxxxxxxxx
https://lists.xenproject.org/xen-changelog

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.