commit | 239af7c7132a617f9dcd05da1dc92b96bc6d0645 | [log] [tgz] |
---|---|---|
author | Juergen Gross <jgross@suse.com> | Tue Oct 14 11:00:18 2014 +0200 |
committer | David Vrabel <david.vrabel@citrix.com> | Thu Oct 23 16:24:01 2014 +0100 |
tree | 74c821845a28a43278cf4522f0871f70dcbb2ba4 | |
parent | fd8b79511349efd1f0decea920f61b93acb34a75 [diff] |
x86/xen: avoid writing to freed memory after race in p2m handling In case a race was detected during allocation of a new p2m tree element in alloc_p2m() the new allocated mid_mfn page is freed without updating the pointer to the found value in the tree. This will result in overwriting the just freed page with the mfn of the p2m leaf. Signed-off-by: Juergen Gross <jgross@suse.com> Signed-off-by: David Vrabel <david.vrabel@citrix.com>