tree 0100ba4e3bf5510de288dd35ee5ea1d0e5ed6857
parent 1105f6ce20debe482461418d62a2ba10b3e2f54c
author Matthew Wilcox (Oracle) <willy@infradead.org> 1703177637 +0000
committer Michael Kochera <kochera@google.com> 1706658895 +0000

ida: Fix crash in ida_free when the bitmap is empty

[ Upstream commit af73483f4e8b6f5c68c9aa63257bdd929a9c194a ]

The IDA usually detects double-frees, but that detection failed to
consider the case when there are no nearby IDs allocated and so we have a
NULL bitmap rather than simply having a clear bit.  Add some tests to the
test-suite to be sure we don't inadvertently reintroduce this problem.
Unfortunately they're quite noisy so include a message to disregard
the warnings.

BUG=b/321923134
TEST=None
RELEASE_NOTE=Fixed CVE-2023-6915 in the linux kernel.

cos-patch: security-high
Reported-by: Zhenghan Wang <wzhmmmmm@gmail.com>
Change-Id: I79ae1d6880159712099af2b541b3909f5244b2b3
Signed-off-by: Matthew Wilcox (Oracle) <willy@infradead.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Reviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/64331
Tested-by: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
Reviewed-by: Oleksandr Tymoshenko <ovt@google.com>
