Commit 3dc5e059 authored by Andrii Nakryiko's avatar Andrii Nakryiko Committed by Daniel Borkmann

libbpf: Fix memory leak/double free issue

Coverity scan against Github libbpf code found the issue of not freeing memory and
leaving already freed memory still referenced from bpf_program. Fix it by
re-assigning successfully reallocated memory sooner.

Fixes: 2993e051 ("tools/bpf: add support to read .BTF.ext sections")
Signed-off-by: default avatarAndrii Nakryiko <andriin@fb.com>
Signed-off-by: default avatarDaniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20191107020855.3834758-2-andriin@fb.com
parent 9656b346
...@@ -3523,6 +3523,7 @@ bpf_program__reloc_text(struct bpf_program *prog, struct bpf_object *obj, ...@@ -3523,6 +3523,7 @@ bpf_program__reloc_text(struct bpf_program *prog, struct bpf_object *obj,
pr_warn("oom in prog realloc\n"); pr_warn("oom in prog realloc\n");
return -ENOMEM; return -ENOMEM;
} }
prog->insns = new_insn;
if (obj->btf_ext) { if (obj->btf_ext) {
err = bpf_program_reloc_btf_ext(prog, obj, err = bpf_program_reloc_btf_ext(prog, obj,
...@@ -3534,7 +3535,6 @@ bpf_program__reloc_text(struct bpf_program *prog, struct bpf_object *obj, ...@@ -3534,7 +3535,6 @@ bpf_program__reloc_text(struct bpf_program *prog, struct bpf_object *obj,
memcpy(new_insn + prog->insns_cnt, text->insns, memcpy(new_insn + prog->insns_cnt, text->insns,
text->insns_cnt * sizeof(*insn)); text->insns_cnt * sizeof(*insn));
prog->insns = new_insn;
prog->main_prog_cnt = prog->insns_cnt; prog->main_prog_cnt = prog->insns_cnt;
prog->insns_cnt = new_cnt; prog->insns_cnt = new_cnt;
pr_debug("added %zd insn from %s to prog %s\n", pr_debug("added %zd insn from %s to prog %s\n",
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment