All of lore.kernel.org
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH] crypto: afalg: fix a NULL pointer dereference
@ 2017-11-06  6:21 Longpeng(Mike)
  2017-11-06 10:21 ` Gonglei (Arei)
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: Longpeng(Mike) @ 2017-11-06  6:21 UTC (permalink / raw)
  To: berrange, pbonzini, arei.gonglei; +Cc: longpeng2, qemu-devel

Test-crypto-hash calls qcrypto_hash_bytesv/digest/base64 with
errp=NULL, this will cause a NULL poniter deference if afalg_driver
doesn't support requested algos:
    ret = qcrypto_hash_afalg_driver.hash_bytesv(alg, iov, niov,
                                                result, resultlen,
                                                errp);
    if (ret == 0) {
        return ret;
    }

    error_free(*errp);  // <--- here

So we must check 'errp & *errp' before dereference.

Signed-off-by: Longpeng(Mike) <longpeng2@huawei.com>
---
 crypto/hash.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/crypto/hash.c b/crypto/hash.c
index ac59c63..c464c78 100644
--- a/crypto/hash.c
+++ b/crypto/hash.c
@@ -60,7 +60,9 @@ int qcrypto_hash_bytesv(QCryptoHashAlgorithm alg,
      * TODO:
      * Maybe we should treat some afalg errors as fatal
      */
-    error_free(*errp);
+    if (errp && *errp) {
+        error_free(*errp);
+    }
 #endif
 
     return qcrypto_hash_lib_driver.hash_bytesv(alg, iov, niov,
-- 
1.8.3.1

^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2017-11-07  9:33 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-11-06  6:21 [Qemu-devel] [PATCH] crypto: afalg: fix a NULL pointer dereference Longpeng(Mike)
2017-11-06 10:21 ` Gonglei (Arei)
2017-11-06 17:00 ` Eric Blake
2017-11-07  2:27   ` Longpeng (Mike)
2017-11-07  9:16     ` Daniel P. Berrange
2017-11-07  9:32       ` Longpeng (Mike)
2017-11-06 17:18 ` Stefan Hajnoczi
2017-11-07  1:13   ` Longpeng (Mike)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.