mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] ia64/sn/hwperf: check seq_open return value to avoid NULL deref
@ 2018-08-16 11:42 Rasmus Villemoes
  0 siblings, 0 replies; only message in thread
From: Rasmus Villemoes @ 2018-08-16 11:42 UTC (permalink / raw)
  To: Tony Luck, Fenghua Yu; +Cc: Rasmus Villemoes, linux-ia64, linux-kernel

This code should check the return value of seq_open(); if it failed,
file->private_data is NULL. But in that case we then need to dispose of
objbuf to prevent a resource leak.

Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
---
 arch/ia64/sn/kernel/sn2/sn_hwperf.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/arch/ia64/sn/kernel/sn2/sn_hwperf.c b/arch/ia64/sn/kernel/sn2/sn_hwperf.c
index 55febd65911a..9e36f0b7d9ae 100644
--- a/arch/ia64/sn/kernel/sn2/sn_hwperf.c
+++ b/arch/ia64/sn/kernel/sn2/sn_hwperf.c
@@ -947,8 +947,12 @@ int sn_topology_open(struct inode *inode, struct file *file)
 
 	if ((e = sn_hwperf_enum_objects(&nobj, &objbuf)) == 0) {
 		e = seq_open(file, &sn_topology_seq_ops);
-		seq = file->private_data;
-		seq->private = objbuf;
+		if (e) {
+			vfree(objbuf);
+		} else {
+			seq = file->private_data;
+			seq->private = objbuf;
+		}
 	}
 
 	return e;
-- 
2.16.4


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2018-08-16 11:42 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-08-16 11:42 [PATCH] ia64/sn/hwperf: check seq_open return value to avoid NULL deref Rasmus Villemoes

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®