Vincent Fazio <vfa...@xes-inc.com> writes:

> From: Vincent Fazio <vfa...@gmail.com>
>
> Previously, if the build host's libc did not define MAP_FIXED_NOREPLACE
> or if the running kernel didn't support that flag, it was possible for
> pgd_find_hole_fallback to munmap an incorrect address which could lead to
> SIGSEGV if the range happened to overlap with the mapped address of the
> QEMU binary.
>
>   mmap(0x1000, 22261224, PROT_NONE, MAP_PRIVATE|MAP_ANONYMOUS|MAP_NORESERVE, 
> -1, 0) = 0x7f889d331000
>   munmap(0x1000, 22261224)                = 0
>   --- SIGSEGV {si_signo=SIGSEGV, si_code=SEGV_MAPERR, si_addr=0x84b817} ---
>   ++ killed by SIGSEGV +++
>
> Now, always munmap the address returned by mmap.
>
> Fixes: 2667e069e7b5 ("linux-user: don't use MAP_FIXED in 
> pgd_find_hole_fallback")
> Signed-off-by: Vincent Fazio <vfa...@gmail.com>

Reviewed-by: Alex Bennée <alex.ben...@linaro.org>

-- 
Alex Bennée

Reply via email to