mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Xiyu Yang <xiyuyang19@fudan.edu.cn>,
	Xin Tan <tanxin.ctf@gmail.com>, Christoph Hellwig <hch@lst.de>,
	Sasha Levin <sashal@kernel.org>
Subject: [PATCH AUTOSEL 4.9 09/27] configfs: fix config_item refcnt leak in configfs_rmdir()
Date: Thu, 14 May 2020 14:55:32 -0400	[thread overview]
Message-ID: <20200514185550.21462-9-sashal@kernel.org> (raw)
In-Reply-To: <20200514185550.21462-1-sashal@kernel.org>

From: Xiyu Yang <xiyuyang19@fudan.edu.cn>

[ Upstream commit 8aebfffacfa379ba400da573a5bf9e49634e38cb ]

configfs_rmdir() invokes configfs_get_config_item(), which returns a
reference of the specified config_item object to "parent_item" with
increased refcnt.

When configfs_rmdir() returns, local variable "parent_item" becomes
invalid, so the refcount should be decreased to keep refcount balanced.

The reference counting issue happens in one exception handling path of
configfs_rmdir(). When down_write_killable() fails, the function forgets
to decrease the refcnt increased by configfs_get_config_item(), causing
a refcnt leak.

Fix this issue by calling config_item_put() when down_write_killable()
fails.

Signed-off-by: Xiyu Yang <xiyuyang19@fudan.edu.cn>
Signed-off-by: Xin Tan <tanxin.ctf@gmail.com>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/configfs/dir.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/configfs/dir.c b/fs/configfs/dir.c
index c2ef617d2f97d..c875f246cb0e9 100644
--- a/fs/configfs/dir.c
+++ b/fs/configfs/dir.c
@@ -1537,6 +1537,7 @@ static int configfs_rmdir(struct inode *dir, struct dentry *dentry)
 		spin_lock(&configfs_dirent_lock);
 		configfs_detach_rollback(dentry);
 		spin_unlock(&configfs_dirent_lock);
+		config_item_put(parent_item);
 		return -EINTR;
 	}
 	frag->frag_dead = true;
-- 
2.20.1


  parent reply	other threads:[~2020-05-14 18:59 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-05-14 18:55 [PATCH AUTOSEL 4.9 01/27] Makefile: disallow data races on gcc-10 as well Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 02/27] gcc-common.h: Update for GCC 10 Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 03/27] HID: multitouch: add eGalaxTouch P80H84 support Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 04/27] batman-adv: fix batadv_nc_random_weight_tq Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 05/27] batman-adv: Fix refcnt leak in batadv_show_throughput_override Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 06/27] batman-adv: Fix refcnt leak in batadv_store_throughput_override Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 07/27] batman-adv: Fix refcnt leak in batadv_v_ogm_process Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 08/27] phy: tegra: Select USB_COMMON for usb_get_maximum_speed() Sasha Levin
2020-05-14 18:55 ` Sasha Levin [this message]
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 10/27] bnxt_en: Fix VLAN acceleration handling in bnxt_fix_features() Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 11/27] net/sonic: Fix a resource leak in an error handling path in 'jazz_sonic_probe()' Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 12/27] component: Silence bind error on -EPROBE_DEFER Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 13/27] net/mlx5: Fix forced completion access non initialized command entry Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 14/27] net/mlx5: Fix command entry leak in Internal Error State Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 15/27] dp83640: reverse arguments to list_add_tail Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 16/27] soc: qcom: ipa: IPA endpoints Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 17/27] net: ipa: fix a bug in ipa_endpoint_stop() Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 18/27] net: macsec: preserve ingress frame ordering Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 19/27] net: moxa: Fix a potential double 'free_irq()' Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 20/27] gtp: set NLM_F_MULTI flag in gtp_genl_dump_pdp() Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 21/27] net: usb: qmi_wwan: add support for DW5816e Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 22/27] ceph: fix double unlock in handle_cap_export() Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 23/27] net/mlx4_core: Fix use of ENOSPC around mlx4_counter_alloc() Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 24/27] USB: core: Fix misleading driver bug report Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 25/27] platform/x86: asus-nb-wmi: Do not load on Asus T100TA and T200TA Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 26/27] ARM: futex: Address build warning Sasha Levin
2020-05-14 18:55 ` [PATCH AUTOSEL 4.9 27/27] scripts/decodecode: fix trapping instruction formatting Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20200514185550.21462-9-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=hch@lst.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=tanxin.ctf@gmail.com \
    --cc=xiyuyang19@fudan.edu.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome