From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) by mx.groups.io with SMTP id smtpd.web10.9547.1624877477158870131 for ; Mon, 28 Jun 2021 03:51:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@ibm.com header.s=pp1 header.b=eEoguxLD; spf=pass (domain: linux.ibm.com, ip: 148.163.156.1, mailfrom: dovmurik@linux.ibm.com) Received: from pps.filterd (m0098404.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 15SAYst1104092; Mon, 28 Jun 2021 06:51:16 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=from : to : cc : subject : date : message-id : in-reply-to : references : mime-version : content-transfer-encoding; s=pp1; bh=R7AwzFYlom9UZF/tz8NLZ4WCcPkoE00WSi7T1S8X1z4=; b=eEoguxLDlJMsIOWeMfL/XMm4txyzq4sx0XmuDHUqoNgCfz16lxixJJEgDm77wdwWJNow 55HBmxm3Jq/4fLCgVbwwP8wJSjL0YNYhj1RB0EEDWDKfCzlJ5WHujzfvajjGDsBv55oh J2uoajG1HGEQO/Ghm9yveNRV8o1EyV+POX0M6laN2VEFnmrCwyebN6CWj+CodDEYXOEi cqDAJQWhOQ+y6RBkwFGAGFMjdBzB2QLtldjNBsIM2TYaHBDRmBv0Yad+p23WLIOXMfae zc62VdNuxqbaNAknzNFfljAVA93k+UDnsCY3ukvMsy2YTQK1LLTlx9OuYQ70VtOJbKyR uw== Received: from pps.reinject (localhost [127.0.0.1]) by mx0a-001b2d01.pphosted.com with ESMTP id 39fcfu8uuw-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 28 Jun 2021 06:51:16 -0400 Received: from m0098404.ppops.net (m0098404.ppops.net [127.0.0.1]) by pps.reinject (8.16.0.43/8.16.0.43) with SMTP id 15SAZ2du105257; Mon, 28 Jun 2021 06:51:16 -0400 Received: from ppma05wdc.us.ibm.com (1b.90.2fa9.ip4.static.sl-reverse.com [169.47.144.27]) by mx0a-001b2d01.pphosted.com with ESMTP id 39fcfu8uug-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 28 Jun 2021 06:51:16 -0400 Received: from pps.filterd (ppma05wdc.us.ibm.com [127.0.0.1]) by ppma05wdc.us.ibm.com (8.16.1.2/8.16.1.2) with SMTP id 15SAgBA2011498; Mon, 28 Jun 2021 10:51:15 GMT Received: from b01cxnp22036.gho.pok.ibm.com (b01cxnp22036.gho.pok.ibm.com [9.57.198.26]) by ppma05wdc.us.ibm.com with ESMTP id 39duva96dv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 28 Jun 2021 10:51:15 +0000 Received: from b01ledav006.gho.pok.ibm.com (b01ledav006.gho.pok.ibm.com [9.57.199.111]) by b01cxnp22036.gho.pok.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 15SApET58127318 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 28 Jun 2021 10:51:14 GMT Received: from b01ledav006.gho.pok.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7A16BAC05B; Mon, 28 Jun 2021 10:51:14 +0000 (GMT) Received: from b01ledav006.gho.pok.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 52D03AC05F; Mon, 28 Jun 2021 10:51:14 +0000 (GMT) Received: from localhost.localdomain (unknown [9.2.130.16]) by b01ledav006.gho.pok.ibm.com (Postfix) with ESMTP; Mon, 28 Jun 2021 10:51:14 +0000 (GMT) From: "Dov Murik" To: devel@edk2.groups.io Cc: Dov Murik , Ard Biesheuvel , Jordan Justen , James Bottomley , Tobin Feldman-Fitzthum , Laszlo Ersek Subject: [PATCH v3 2/5] OvmfPkg/X86QemuLoadImageLib: plug cmdline blob leak on success Date: Mon, 28 Jun 2021 10:51:07 +0000 Message-Id: <20210628105110.379951-3-dovmurik@linux.ibm.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210628105110.379951-1-dovmurik@linux.ibm.com> References: <20210628105110.379951-1-dovmurik@linux.ibm.com> MIME-Version: 1.0 X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: hTRPqzscOoQm8g318B01PE12xxY30Ked X-Proofpoint-GUID: Gr6nsC2ZlwrJ4AuYUBbR0bgP2HgZidB0 X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.391,18.0.790 definitions=2021-06-28_09:2021-06-25,2021-06-28 signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 mlxscore=0 phishscore=0 spamscore=0 suspectscore=0 lowpriorityscore=0 bulkscore=0 adultscore=0 impostorscore=0 priorityscore=1501 mlxlogscore=999 malwarescore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2104190000 definitions=main-2106280070 Content-Transfer-Encoding: quoted-printable When QemuLoadKernelImage() ends successfully, the command-line blob is not freed, even though it is not used elsewhere (its content is already copied to KernelLoadedImage->LoadOptions). The memory leak bug was introduced in commit 7c47d89003a6 ("OvmfPkg: implement QEMU loader library for X86 with legacy fallback", 2020-03-05). Cc: Ard Biesheuvel Cc: Jordan Justen Cc: James Bottomley Cc: Tobin Feldman-Fitzthum Reported-by: Laszlo Ersek Fixes: 7c47d89003a6f8f7f6f0ce8ca7d3e87c630d14cc Signed-off-by: Dov Murik --- OvmfPkg/Library/X86QemuLoadImageLib/X86QemuLoadImageLib.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/OvmfPkg/Library/X86QemuLoadImageLib/X86QemuLoadImageLib.c b/Ov= mfPkg/Library/X86QemuLoadImageLib/X86QemuLoadImageLib.c index 1177582ab051..6b1e7e649014 100644 --- a/OvmfPkg/Library/X86QemuLoadImageLib/X86QemuLoadImageLib.c +++ b/OvmfPkg/Library/X86QemuLoadImageLib/X86QemuLoadImageLib.c @@ -446,14 +446,16 @@ QemuLoadKernelImage ( }=0D =0D *ImageHandle =3D KernelImageHandle;=0D - return EFI_SUCCESS;=0D + Status =3D EFI_SUCCESS;=0D =0D FreeCommandLine:=0D if (CommandLineSize > 0) {=0D FreePool (CommandLine);=0D }=0D UnloadImage:=0D - gBS->UnloadImage (KernelImageHandle);=0D + if (EFI_ERROR (Status)) {=0D + gBS->UnloadImage (KernelImageHandle);=0D + }=0D =0D return Status;=0D }=0D --=20 2.25.1