From: Mohamed Ghannam Date: Wed, 3 Jan 2018 21:06:06 +0000 (+0000) Subject: RDS: null pointer dereference in rds_atomic_free_op X-Git-Url: http://git.openpandora.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=57e49cc5d8048f4274b3b2c8ec075f656f8a3ed1;p=pandora-kernel.git RDS: null pointer dereference in rds_atomic_free_op commit 7d11f77f84b27cef452cee332f4e469503084737 upstream. set rm->atomic.op_active to 0 when rds_pin_pages() fails or the user supplied address is invalid, this prevents a NULL pointer usage in rds_atomic_free_op() Signed-off-by: Mohamed Ghannam Acked-by: Santosh Shilimkar Signed-off-by: David S. Miller Signed-off-by: Ben Hutchings --- diff --git a/net/rds/rdma.c b/net/rds/rdma.c index 6bb8a4ca3b7a..6fcd65a923ea 100644 --- a/net/rds/rdma.c +++ b/net/rds/rdma.c @@ -855,6 +855,7 @@ int rds_cmsg_atomic(struct rds_sock *rs, struct rds_message *rm, err: if (page) put_page(page); + rm->atomic.op_active = 0; kfree(rm->atomic.op_notifier); return ret;