From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1757543Ab2AKPYT (ORCPT ); Wed, 11 Jan 2012 10:24:19 -0500 Received: from mail-iy0-f174.google.com ([209.85.210.174]:38167 "EHLO mail-iy0-f174.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1757247Ab2AKPYQ (ORCPT ); Wed, 11 Jan 2012 10:24:16 -0500 From: Jiang Liu To: linux-kernel@vger.kernel.org Cc: Jiang Liu , Ananth N Mavinakayanahalli , Anil S Keshavamurthy , "David S . Miller" , Masami Hiramatsu , Jim Keniston , Jun Ma , stable@kernel.org, Jiang Liu Subject: [PATCH] kprobes: fix a memory leak in function pre_handler_kretprobe() Date: Wed, 11 Jan 2012 23:21:51 +0800 Message-Id: <1326295311-10985-1-git-send-email-jiang.liu@huawei.com> X-Mailer: git-send-email 1.7.5.4 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Jiang Liu In function pre_handler_kretprobe(), the allocated kretprobe_instance object will be leaked if the entry_handler callback returns non-zero. This may cause all the preallocated kretprobe_instance objects exhausted. This issue could be reproduced by changing samples/kprobes/kretprobe_example.c to probe "mutex_unlock". And the fix is straight forward, just put the allocated kretprobe_instance object back onto the free_instances list. Signed-off-by: Jiang Liu Acked-by: Jim Keniston Acked-by: Ananth N Mavinakayanahalli --- kernel/kprobes.c | 6 +++++- 1 files changed, 5 insertions(+), 1 deletions(-) diff --git a/kernel/kprobes.c b/kernel/kprobes.c index e5d8464..2423295 100644 --- a/kernel/kprobes.c +++ b/kernel/kprobes.c @@ -1673,8 +1673,12 @@ static int __kprobes pre_handler_kretprobe(struct kprobe *p, ri->rp = rp; ri->task = current; - if (rp->entry_handler && rp->entry_handler(ri, regs)) + if (rp->entry_handler && rp->entry_handler(ri, regs)) { + spin_lock_irqsave(&rp->lock, flags); + hlist_add_head(&ri->hlist, &rp->free_instances); + spin_unlock_irqrestore(&rp->lock, flags); return 0; + } arch_prepare_kretprobe(ri, regs); -- 1.7.5.4