From 03056113c27189d095da540e9e16adaad720291a Mon Sep 17 00:00:00 2001 From: Peng Sun Date: Tue, 19 Mar 2019 23:23:21 +0800 Subject: [PATCH] bpf: drop refcount if bpf_map_new_fd() fails in map_create() mainline inclusion from mainline-5.0 commit 352d20d611414715353ee65fc206ee57ab1a6984 category: bugfix bugzilla: 11102 CVE: NA ------------------------------------------------- In bpf/syscall.c, map_create() first set map->usercnt to 1, a file descriptor is supposed to return to userspace. When bpf_map_new_fd() fails, drop the refcount. Fixes: bd5f5f4ecb78 ("bpf: Add BPF_MAP_GET_FD_BY_ID") Signed-off-by: Peng Sun Acked-by: Martin KaFai Lau Signed-off-by: Alexei Starovoitov Signed-off-by: Daniel Borkmann (cherry picked from commit 352d20d611414715353ee65fc206ee57ab1a6984) Signed-off-by: Zhen Lei Reviewed-by: Yang Yingliang Signed-off-by: Yang Yingliang --- kernel/bpf/syscall.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c index 0599aa1e5d93..1cb54b5aeb17 100644 --- a/kernel/bpf/syscall.c +++ b/kernel/bpf/syscall.c @@ -559,12 +559,12 @@ static int map_create(union bpf_attr *attr) err = bpf_map_new_fd(map, f_flags); if (err < 0) { /* failed to allocate fd. - * bpf_map_put() is needed because the above + * bpf_map_put_with_uref() is needed because the above * bpf_map_alloc_id() has published the map * to the userspace and the userspace may * have refcnt-ed it through BPF_MAP_GET_FD_BY_ID. */ - bpf_map_put(map); + bpf_map_put_with_uref(map); return err; } -- GitLab