xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing)
authorCathy Avery <cathy.avery@oracle.com>
Fri, 2 Oct 2015 13:35:01 +0000 (09:35 -0400)
committerBen Hutchings <ben@decadent.org.uk>
Tue, 17 Nov 2015 15:54:43 +0000 (15:54 +0000)
commit a54c8f0f2d7df525ff997e2afe71866a1a013064 upstream.

xen-blkfront will crash if the check to talk_to_blkback()
in blkback_changed()(XenbusStateInitWait) returns an error.
The driver data is freed and info is set to NULL. Later during
the close process via talk_to_blkback's call to xenbus_dev_fatal()
the null pointer is passed to and dereference in blkfront_closing.

Signed-off-by: Cathy Avery <cathy.avery@oracle.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
drivers/block/xen-blkfront.c

index 96b8cb7..857f363 100644 (file)
@@ -1292,7 +1292,8 @@ static void blkback_changed(struct xenbus_device *dev,
                        break;
                /* Missed the backend's Closing state -- fallthrough */
        case XenbusStateClosing:
-               blkfront_closing(info);
+               if (info)
+                       blkfront_closing(info);
                break;
        }
 }