提交 b305f7ed 编写于 作者: Y Yi Wang 提交者: Paul Moore

audit: fix potential null dereference 'context->module.name'

The variable 'context->module.name' may be null pointer when
kmalloc return null, so it's better to check it before using
to avoid null dereference.
Another one more thing this patch does is using kstrdup instead
of (kmalloc + strcpy), and signal a lost record via audit_log_lost.

Cc: stable@vger.kernel.org # 4.11
Signed-off-by: NYi Wang <wang.yi59@zte.com.cn>
Reviewed-by: NJiang Biao <jiang.biao2@zte.com.cn>
Reviewed-by: NRichard Guy Briggs <rgb@redhat.com>
Signed-off-by: NPaul Moore <paul@paul-moore.com>
上级 5b713886
...@@ -1279,8 +1279,12 @@ static void show_special(struct audit_context *context, int *call_panic) ...@@ -1279,8 +1279,12 @@ static void show_special(struct audit_context *context, int *call_panic)
break; break;
case AUDIT_KERN_MODULE: case AUDIT_KERN_MODULE:
audit_log_format(ab, "name="); audit_log_format(ab, "name=");
if (context->module.name) {
audit_log_untrustedstring(ab, context->module.name); audit_log_untrustedstring(ab, context->module.name);
kfree(context->module.name); kfree(context->module.name);
} else
audit_log_format(ab, "(null)");
break; break;
} }
audit_log_end(ab); audit_log_end(ab);
...@@ -2411,8 +2415,9 @@ void __audit_log_kern_module(char *name) ...@@ -2411,8 +2415,9 @@ void __audit_log_kern_module(char *name)
{ {
struct audit_context *context = audit_context(); struct audit_context *context = audit_context();
context->module.name = kmalloc(strlen(name) + 1, GFP_KERNEL); context->module.name = kstrdup(name, GFP_KERNEL);
strcpy(context->module.name, name); if (!context->module.name)
audit_log_lost("out of memory in __audit_log_kern_module");
context->type = AUDIT_KERN_MODULE; context->type = AUDIT_KERN_MODULE;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册