From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
Hitoshi Mitake <mitake@dcl.info.waseda.ac.jp>,
Steve French <sfrench@us.ibm.com>
Subject: [46/99] CIFS: Fixing to avoid invalid kfree() in cifs_get_tcp_session()
Date: Fri, 06 Nov 2009 14:14:44 -0800 [thread overview]
Message-ID: <20091106221544.917678408@mini.kroah.org> (raw)
In-Reply-To: <20091106221850.GA15408@kroah.com>
[-- Attachment #1: cifs-fixing-to-avoid-invalid-kfree-in-cifs_get_tcp_session.patch --]
[-- Type: text/plain, Size: 4197 bytes --]
2.6.31-stable review patch. If anyone has any objections, please let us know.
------------------
From: Steve French <sfrench@us.ibm.com>
commit 8347a5cdd1422eea0470ed586274c7f29e274b47 upstream.
trivial bug in fs/cifs/connect.c .
The bug is caused by fail of extract_hostname()
when mounting cifs file system.
This is the situation when I noticed this bug.
% sudo mount -t cifs //192.168.10.208 mountpoint -o options...
Then my kernel says,
[ 1461.807776] ------------[ cut here ]------------
[ 1461.807781] kernel BUG at mm/slab.c:521!
[ 1461.807784] invalid opcode: 0000 [#2] PREEMPT SMP
[ 1461.807790] last sysfs file:
/sys/devices/pci0000:00/0000:00:1e.0/0000:09:02.0/resource
[ 1461.807793] CPU 0
[ 1461.807796] Modules linked in: nls_iso8859_1 usbhid sbp2 uhci_hcd
ehci_hcd i2c_i801 ohci1394 ieee1394 psmouse serio_raw pcspkr sky2 usbcore
evdev
[ 1461.807816] Pid: 3446, comm: mount Tainted: G D 2.6.32-rc2-vanilla
[ 1461.807820] RIP: 0010:[<ffffffff810b888e>] [<ffffffff810b888e>]
kfree+0x63/0x156
[ 1461.807829] RSP: 0018:ffff8800b4f7fbb8 EFLAGS: 00010046
[ 1461.807832] RAX: ffffea00033fff98 RBX: ffff8800afbae7e2 RCX:
0000000000000000
[ 1461.807836] RDX: ffffea0000000000 RSI: 000000000000005c RDI:
ffffffffffffffea
[ 1461.807839] RBP: ffff8800b4f7fbf8 R08: 0000000000000001 R09:
0000000000000000
[ 1461.807842] R10: 0000000000000000 R11: ffff8800b4f7fbf8 R12:
00000000ffffffea
[ 1461.807845] R13: ffff8800afb23000 R14: ffff8800b4f87bc0 R15:
ffffffffffffffea
[ 1461.807849] FS: 00007f52b6f187c0(0000) GS:ffff880007600000(0000)
knlGS:0000000000000000
[ 1461.807852] CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005003b
[ 1461.807855] CR2: 0000000000613000 CR3: 00000000af8f9000 CR4:
00000000000006f0
[ 1461.807858] DR0: 0000000000000000 DR1: 0000000000000000 DR2:
0000000000000000
[ 1461.807861] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7:
0000000000000400
[ 1461.807865] Process mount (pid: 3446, threadinfo ffff8800b4f7e000, task
ffff8800950e4380)
[ 1461.807867] Stack:
[ 1461.807869] 0000000000000202 0000000000000282 ffff8800b4f7fbf8
ffff8800afbae7e2
[ 1461.807876] <0> 00000000ffffffea ffff8800afb23000 ffff8800b4f87bc0
ffff8800b4f7fc28
[ 1461.807884] <0> ffff8800b4f7fcd8 ffffffff81159f6d ffffffff81147bc2
ffffffff816bfb48
[ 1461.807892] Call Trace:
[ 1461.807899] [<ffffffff81159f6d>] cifs_get_tcp_session+0x440/0x44b
[ 1461.807904] [<ffffffff81147bc2>] ? find_nls+0x1c/0xe9
[ 1461.807909] [<ffffffff8115b889>] cifs_mount+0x16bc/0x2167
[ 1461.807917] [<ffffffff814455bd>] ? _spin_unlock+0x30/0x4b
[ 1461.807923] [<ffffffff81150da9>] cifs_get_sb+0xa5/0x1a8
[ 1461.807928] [<ffffffff810c1b94>] vfs_kern_mount+0x56/0xc9
[ 1461.807933] [<ffffffff810c1c64>] do_kern_mount+0x47/0xe7
[ 1461.807938] [<ffffffff810d8632>] do_mount+0x712/0x775
[ 1461.807943] [<ffffffff810d671f>] ? copy_mount_options+0xcf/0x132
[ 1461.807948] [<ffffffff810d8714>] sys_mount+0x7f/0xbf
[ 1461.807953] [<ffffffff8144509a>] ? lockdep_sys_exit_thunk+0x35/0x67
[ 1461.807960] [<ffffffff81011cc2>] system_call_fastpath+0x16/0x1b
[ 1461.807963] Code: 00 00 00 00 ea ff ff 48 c1 e8 0c 48 6b c0 68 48 01 d0
66 83 38 00 79 04 48 8b 40 10 66 83 38 00 79 04 48 8b 40 10 80 38 00 78 04
<0f> 0b eb fe 4c 8b 70 58 4c 89 ff 41 8b 76 4c e8 b8 49 fb ff e8
[ 1461.808022] RIP [<ffffffff810b888e>] kfree+0x63/0x156
[ 1461.808027] RSP <ffff8800b4f7fbb8>
[ 1461.808031] ---[ end trace ffe26fcdc72c0ce4 ]---
The reason of this bug is that the error handling code of
cifs_get_tcp_session()
calls kfree() when corresponding kmalloc() failed.
(The kmalloc() is called by extract_hostname().)
Signed-off-by: Hitoshi Mitake <mitake@dcl.info.waseda.ac.jp>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
fs/cifs/connect.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/fs/cifs/connect.c
+++ b/fs/cifs/connect.c
@@ -1556,7 +1556,8 @@ cifs_get_tcp_session(struct smb_vol *vol
out_err:
if (tcp_ses) {
- kfree(tcp_ses->hostname);
+ if (!IS_ERR(tcp_ses->hostname))
+ kfree(tcp_ses->hostname);
if (tcp_ses->ssocket)
sock_release(tcp_ses->ssocket);
kfree(tcp_ses);
next prev parent reply other threads:[~2009-11-06 22:36 UTC|newest]
Thread overview: 104+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20091106221358.309857998@mini.kroah.org>
2009-11-06 22:18 ` [00/99] 2.6.31.6 stable review Greg KH
2009-11-06 22:13 ` [01/99] fs: pipe.c null pointer dereference Greg KH
2009-11-06 22:14 ` [02/99] pci: increase alignment to make more space for hidden code Greg KH
2009-11-06 22:14 ` [03/99] libata: fix internal command failure handling Greg KH
2009-11-06 22:14 ` [04/99] libata: fix PMP initialization Greg KH
2009-11-06 22:14 ` [05/99] sata_nv: make sure link is brough up online when skipping hardreset Greg KH
2009-11-06 22:14 ` [06/99] nfs: Fix nfs_parse_mount_options() kfree() leak Greg KH
2009-11-06 22:14 ` [07/99] KVM: use proper hrtimer function to retrieve expiration time Greg KH
2009-11-06 22:14 ` [08/99] KVM: ignore reads from AMDs C1E enabled MSR Greg KH
2009-11-06 22:14 ` [09/99] futex: Handle spurious wake up Greg KH
2009-11-06 22:14 ` [10/99] futex: Check for NULL keys in match_futex Greg KH
2009-11-06 22:14 ` [11/99] futex: Move drop_futex_key_refs out of spinlocked region Greg KH
2009-11-06 22:14 ` [12/99] futex: Fix spurious wakeup for requeue_pi really Greg KH
2009-11-06 22:14 ` [13/99] ahci: revert "Restore SB600 sata controller 64 bit DMA" Greg KH
2009-11-06 22:14 ` [14/99] sparc64: Set IRQF_DISABLED on LDC channel IRQs Greg KH
2009-11-06 22:14 ` [15/99] sparc: Kill PROM console driver Greg KH
2009-11-06 22:14 ` [16/99] watchdog: Fix rio watchdog probe function Greg KH
2009-11-06 22:14 ` [17/99] Input: synaptics - add another Protege M300 to rate blacklist Greg KH
2009-11-06 22:14 ` [18/99] dm snapshot: free exception store on init failure Greg KH
2009-11-06 22:14 ` [19/99] dm snapshot: sort by chunk size to fix race Greg KH
2009-11-06 22:14 ` [20/99] dm log: userspace fix incorrect luid cast in userspace_ctr Greg KH
2009-11-06 22:14 ` [21/99] dm: add missing del_gendisk to alloc_dev error path Greg KH
2009-11-06 22:14 ` [22/99] dm: dec_pending needs locking to save error value Greg KH
2009-11-06 22:14 ` [23/99] dm exception store: fix failed set_chunk_size error path Greg KH
2009-11-06 22:14 ` [24/99] dm snapshot: lock snapshot while supplying status Greg KH
2009-11-06 22:14 ` [25/99] dm snapshot: require non zero chunk size by end of ctr Greg KH
2009-11-06 22:14 ` [26/99] dm snapshot: use unsigned integer chunk size Greg KH
2009-11-06 22:14 ` [27/99] ray_cs: Fix copy_from_user handling Greg KH
2009-11-06 22:14 ` [28/99] mbind(): fix leak of never putback pages Greg KH
2009-11-06 22:14 ` [29/99] do_mbind(): fix memory leak Greg KH
2009-11-06 22:14 ` [30/99] 8250_pci: add IBM Saturn serial card Greg KH
2009-11-06 22:14 ` [31/99] dpt_i2o: Fix up copy*user Greg KH
2009-11-06 22:14 ` [32/99] dpt_i2o: Fix typo of EINVAL Greg KH
2009-11-06 22:14 ` [33/99] hfsplus: refuse to mount volumes larger than 2TB Greg KH
2009-11-06 22:14 ` [34/99] Driver core: fix driver_register() return value Greg KH
2009-11-06 22:14 ` [35/99] tty: Mark generic_serial users as BROKEN Greg KH
2009-11-06 22:14 ` [36/99] param: fix lots of bugs with writing charp params from sysfs, by leaking mem Greg KH
2009-11-06 22:14 ` [37/99] param: fix NULL comparison on oom Greg KH
2009-11-06 22:14 ` [38/99] param: fix setting arrays of bool Greg KH
2009-11-06 22:14 ` [39/99] USB: serial: sierra driver send_setup() autopm fix Greg KH
2009-11-06 22:14 ` [40/99] USB: option: Patch for Huawei Mobile Broadband E270+ Modem Greg KH
2009-11-06 22:14 ` [41/99] USB: option: Support for AIRPLUS MCD650 Datacard Greg KH
2009-11-06 22:14 ` [42/99] USB: option: TLAYTECH TUE800 support Greg KH
2009-11-06 22:14 ` [43/99] libertas if_usb: Fix crash on 64-bit machines Greg KH
2009-11-06 22:14 ` [44/99] cpuidle: always return with interrupts enabled Greg KH
2009-11-06 22:14 ` [45/99] virtio: order used ring after used index read Greg KH
2009-11-06 22:14 ` Greg KH [this message]
2009-11-06 22:14 ` [47/99] mac80211: fix for incorrect sequence number on hostapd injected frames Greg KH
2009-11-06 22:14 ` [48/99] mac80211: check interface is down before type change Greg KH
2009-11-06 22:14 ` [49/99] x86, UV: Fix information in __uv_hub_info structure Greg KH
2009-11-06 22:14 ` [50/99] x86, UV: Set DELIVERY_MODE=4 for vector=NMI_VECTOR in uv_hub_send_ipi() Greg KH
2009-11-06 22:14 ` [51/99] NOMMU: Dont pass NULL pointers to fput() in do_mmap_pgoff() Greg KH
2009-11-06 22:14 ` [52/99] mm: remove incorrect swap_count() from try_to_unuse() Greg KH
2009-11-06 22:14 ` [53/99] x86-64: Fix register leak in 32-bit syscall audting Greg KH
2009-11-06 22:14 ` [54/99] nilfs2: fix dirty page accounting leak causing hang at write Greg KH
2009-11-06 22:14 ` [55/99] drm/i915: Fix FDI M/N setting according with correct color depth Greg KH
2009-11-06 22:14 ` [56/99] drm/i915: fix to setup display reference clock control on Ironlake Greg KH
2009-11-06 22:14 ` [57/99] drm/i915: fix panel fitting filter coefficient select for Ironlake Greg KH
2009-11-06 22:14 ` [58/99] agp/intel: Add B43 chipset support Greg KH
2009-11-06 22:14 ` [59/99] drm/i915: add " Greg KH
2009-11-06 22:14 ` [60/99] xen/hvc: make sure console output is always emitted, with explicit polling Greg KH
2009-11-06 22:14 ` [61/99] xen: mask extended topology info in cpuid Greg KH
2009-11-06 22:15 ` [62/99] sgi-gru: decrapfiy options_write() function Greg KH
2009-11-06 22:15 ` [63/99] KVM: get_tss_base_addr() should return a gpa_t Greg KH
2009-11-06 22:15 ` [64/99] fuse: prevent fuse_put_request on invalid pointer Greg KH
2009-11-06 22:15 ` [65/99] fuse: fix kunmap in fuse_ioctl_copy_user Greg KH
2009-11-06 22:15 ` [66/99] x86/amd-iommu: Workaround for erratum 63 Greg KH
2009-11-06 22:15 ` [67/99] fsnotify: do not set group for a mark before it is on the i_list Greg KH
2009-11-06 22:15 ` [68/99] mips: fix build of vmlinux.lds Greg KH
2009-11-06 22:15 ` [69/99] alpha: fix build after vmlinux.lds.S cleanup Greg KH
2009-11-06 22:15 ` [70/99] ACPI / PCI: Fix NULL pointer dereference in acpi_get_pci_dev() (rev. 2) Greg KH
2009-11-06 22:15 ` [71/99] Revert "ACPI: Attach the ACPI device to the ACPI handle as early as possible" Greg KH
2009-11-06 22:15 ` [72/99] KEYS: get_instantiation_keyring() should inc the keyring refcount in all cases Greg KH
2009-11-06 22:15 ` [73/99] b43: Fix Bugzilla #14181 and the bug from the previous fix Greg KH
2009-11-06 22:15 ` [74/99] pata_sc1200: Fix crash on boot Greg KH
2009-11-06 22:15 ` [75/99] AF_UNIX: Fix deadlock on connecting to shutdown socket (CVE-2009-3621) Greg KH
2009-11-06 22:15 ` [76/99] ALSA: ice1724 - Make call to set hw params succeed on ESI Juli@ Greg KH
2009-11-06 22:15 ` [77/99] bonding: fix a race condition in calls to slave MII ioctls Greg KH
2009-11-06 22:15 ` [78/99] hwmon: (it87) Fix VID reading on IT8718F/IT8720F Greg KH
2009-11-07 15:37 ` [Stable-review] " Willy Tarreau
2009-11-07 17:52 ` Jean Delvare
2009-11-06 22:15 ` [79/99] netlink: fix typo in initialization (CVE-2009-3612) Greg KH
2009-11-06 22:15 ` [80/99] nfs: Avoid overrun when copying client IP address string Greg KH
2009-11-06 22:15 ` [81/99] nfs: Panic when commit fails Greg KH
2009-11-06 22:15 ` [82/99] NFSv4: Fix a bug when the server returns NFS4ERR_RESOURCE Greg KH
2009-11-06 22:15 ` [83/99] NFSv4: Fix two unbalanced put_rpccred() issues Greg KH
2009-11-06 22:15 ` [84/99] NFSv4: Kill nfs4_renewd_prepare_shutdown() Greg KH
2009-11-06 22:15 ` [85/99] NFSv4: The link() operation should return any delegation on the file Greg KH
2009-11-06 22:15 ` [86/99] powerpc: Remove SMP warning from PowerMac cpufreq Greg KH
2009-11-06 22:15 ` [87/99] vmscan: limit VM_EXEC protection to file pages Greg KH
2009-11-06 22:15 ` [88/99] x86: mce: Clean up thermal throttling state tracking code Greg KH
2009-11-06 22:15 ` [89/99] x86: mce: Fix thermal throttling message storm Greg KH
2009-11-06 22:15 ` [90/99] iwlwifi: fix potential rx buffer loss Greg KH
2009-11-06 22:15 ` [91/99] iwlwifi: reduce noise when skb allocation fails Greg KH
2009-11-06 22:15 ` [92/99] x86/amd-iommu: Un__init function required on shutdown Greg KH
2009-11-06 22:15 ` [93/99] KVM: Prevent kvm_init from corrupting debugfs structures Greg KH
2009-11-06 22:15 ` [94/99] powerpc/pmac: Fix PowerSurge SMP IPI allocation Greg KH
2009-11-06 22:15 ` [95/99] powerpc/pmac: Fix issues with sleep on some powerbooks Greg KH
2009-11-06 22:15 ` [96/99] powerpc/pci: Fix regression in powerpc MSI-X Greg KH
2009-11-06 22:15 ` [97/99] powerpc: Fix some late PowerMac G5 with PCIe ATI graphics Greg KH
2009-11-06 22:15 ` [98/99] sata_via: Remove redundant device ID for VIA VT8261 Greg KH
2009-11-06 22:15 ` [99/99] pata_via: extend the rev_max for VT6330 Greg KH
2009-11-07 18:43 ` [00/99] 2.6.31.6 stable review Rafael J. Wysocki
2009-11-09 17:25 ` Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20091106221544.917678408@mini.kroah.org \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=mitake@dcl.info.waseda.ac.jp \
--cc=sfrench@us.ibm.com \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome