提交 963ecbd4 编写于 作者: H Herbert Xu 提交者: David S. Miller

rhashtable: Fix use-after-free in rhashtable_walk_stop

The commit c4db8848 ("rhashtable:
Move future_tbl into struct bucket_table") introduced a use-after-
free bug in rhashtable_walk_stop because it dereferences tbl after
droping the RCU read lock.

This patch fixes it by moving the RCU read unlock down to the bottom
of rhashtable_walk_stop.  In fact this was how I had it originally
but it got dropped while rearranging patches because this one
depended on the async freeing of bucket_table.
Signed-off-by: NHerbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 0034de41
...@@ -854,10 +854,8 @@ void rhashtable_walk_stop(struct rhashtable_iter *iter) ...@@ -854,10 +854,8 @@ void rhashtable_walk_stop(struct rhashtable_iter *iter)
struct rhashtable *ht; struct rhashtable *ht;
struct bucket_table *tbl = iter->walker->tbl; struct bucket_table *tbl = iter->walker->tbl;
rcu_read_unlock();
if (!tbl) if (!tbl)
return; goto out;
ht = iter->ht; ht = iter->ht;
...@@ -869,6 +867,9 @@ void rhashtable_walk_stop(struct rhashtable_iter *iter) ...@@ -869,6 +867,9 @@ void rhashtable_walk_stop(struct rhashtable_iter *iter)
mutex_unlock(&ht->mutex); mutex_unlock(&ht->mutex);
iter->p = NULL; iter->p = NULL;
out:
rcu_read_unlock();
} }
EXPORT_SYMBOL_GPL(rhashtable_walk_stop); EXPORT_SYMBOL_GPL(rhashtable_walk_stop);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册