mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/2] lockd: fix two bugs on nlmclnt_find_lockowner() failure path
@ 2026-08-19  7:46 Ran Hongyun
  2026-08-19  7:46 ` [PATCH 1/2] lockd: fix NULL pointer dereference in nlmclnt_locks_release_private Ran Hongyun
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Ran Hongyun @ 2026-08-19  7:46 UTC (permalink / raw)
  To: trondmy, anna, cel, jlayton, viro, bcodding
  Cc: linux-nfs, linux-kernel, ranhongyun1, chengzhihao1, yangerkun, yi.zhang

Both bugs are triggered when nlmclnt_find_lockowner() returns NULL
due to allocation failure in nlmclnt_proc():

Patch 1 fixes a NULL pointer dereference: nlmclnt_locks_init_private()
unconditionally sets fl->fl_ops before checking whether owner is NULL,
so locks_release_private() later calls fl_release_private which
dereferences the NULL owner. Fix by inlining the function so that
fl_ops is only set after the owner is valid.

Patch 2 fixes a reference leak: call->a_callback_data has not been
assigned when nlmclnt_release_call() is invoked on the error path,
so nlmclnt_ops->nlmclnt_release_call(NULL) skips cleanup and the
references taken by nlmclnt_alloc_call() are never freed. Fix by
moving the assignment before the lockowner check.

Ran Hongyun (2):
  lockd: fix NULL pointer dereference in nlmclnt_locks_release_private
  lockd: fix reference leak on lockowner allocation failure in
    nlmclnt_proc

 fs/lockd/clntproc.c | 19 +++++++------------
 1 file changed, 7 insertions(+), 12 deletions(-)

-- 
2.52.0


^ permalink raw reply	[flat|nested] 8+ messages in thread
* Re: [PATCH v2] squashfs: Add dictionary size range check to prevent shift-out-of-bounds
@ 2026-07-22  6:21 Phillip Lougher
  2026-09-16  7:43 ` [PATCH 0/2] lockd: fix two bugs on nlmclnt_find_lockowner() failure path Ran Hongyun
  0 siblings, 1 reply; 8+ messages in thread
From: Phillip Lougher @ 2026-07-22  6:21 UTC (permalink / raw)
  To: Ran Hongyun
  Cc: linux-kernel, chengzhihao1, yangerkun, yi.zhang, brauner, Andrew Morton



On 13/07/2026 12:55, Ran Hongyun wrote:
> When an abnormal SquashFS image (COMP_OPTS flag is 1 but dictionary size
> is 0) is mounted, and performs shift operations using dictionarysize, the
> shift exponent is -1, causing a shift-out-of-bounds.
> 
> Detail as below:
> squashfs_comp_opts(msblk, buffer, length)
>    squashfs_xz_comp_opts()
>      if (comp_opts)
>        n = ffs(opts->dict_size) - 1;<----opts->dict_size=0, n=-1
>        if (opts->dict_size != (1 << n) && opts->dict_size !=
> 	  	(1 << n) + (1 << (n + 1))) <----shift-out-of-bounds
> 
> Fix it by adding a dictionary size range check before the shift operation.

Reviewed-by: Phillip Lougher <phillip@squashfs.org.uk>

Andrew Morton handles patch submission to Linus for me.  CC'ing him.

Phillip




^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-16  7:51 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-19  7:46 [PATCH 0/2] lockd: fix two bugs on nlmclnt_find_lockowner() failure path Ran Hongyun
2026-08-19  7:46 ` [PATCH 1/2] lockd: fix NULL pointer dereference in nlmclnt_locks_release_private Ran Hongyun
2026-08-19  7:46 ` [PATCH 2/2] lockd: fix reference leak on lockowner allocation failure in nlmclnt_proc Ran Hongyun
2026-08-19 12:06 ` [PATCH 0/2] lockd: fix two bugs on nlmclnt_find_lockowner() failure path Jeff Layton
2026-08-20 14:45 ` Jeff Layton
2026-09-16  7:01   ` Ran Hongyun
2026-09-16  7:07   ` Ran Hongyun
  -- strict thread matches above, loose matches on Subject: below --
2026-07-22  6:21 [PATCH v2] squashfs: Add dictionary size range check to prevent shift-out-of-bounds Phillip Lougher
2026-09-16  7:43 ` [PATCH 0/2] lockd: fix two bugs on nlmclnt_find_lockowner() failure path Ran Hongyun

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®