提交 a1f05514 编写于 作者: K Kinglong Mee 提交者: J. Bruce Fields

NFS4: Avoid NULL reference or double free in nfsd4_fslocs_free()

If fsloc_parse() failed at kzalloc(), fs/nfsd/export.c
 411
 412         fsloc->locations = kzalloc(fsloc->locations_count
 413                         * sizeof(struct nfsd4_fs_location), GFP_KERNEL);
 414         if (!fsloc->locations)
 415                 return -ENOMEM;

svc_export_parse() will call nfsd4_fslocs_free() with fsloc->locations = NULL,
so that, "kfree(fsloc->locations[i].path);" will cause a crash.

If fsloc_parse() failed after that, fsloc_parse() will call nfsd4_fslocs_free(),
and svc_export_parse() will call it again, so that, a double free is caused.

This patch checks the fsloc->locations, and set to NULL after it be freed.
Signed-off-by: NKinglong Mee <kinglongmee@gmail.com>
Signed-off-by: NJ. Bruce Fields <bfields@redhat.com>
上级 a5cddc88
...@@ -295,13 +295,19 @@ svc_expkey_update(struct cache_detail *cd, struct svc_expkey *new, ...@@ -295,13 +295,19 @@ svc_expkey_update(struct cache_detail *cd, struct svc_expkey *new,
static void nfsd4_fslocs_free(struct nfsd4_fs_locations *fsloc) static void nfsd4_fslocs_free(struct nfsd4_fs_locations *fsloc)
{ {
struct nfsd4_fs_location *locations = fsloc->locations;
int i; int i;
if (!locations)
return;
for (i = 0; i < fsloc->locations_count; i++) { for (i = 0; i < fsloc->locations_count; i++) {
kfree(fsloc->locations[i].path); kfree(locations[i].path);
kfree(fsloc->locations[i].hosts); kfree(locations[i].hosts);
} }
kfree(fsloc->locations);
kfree(locations);
fsloc->locations = NULL;
} }
static void svc_export_put(struct kref *ref) static void svc_export_put(struct kref *ref)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册