summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDanilo Krummrich <danilokrummrich@dk-develop.de>2018-04-10 16:31:38 -0700
committerBen Hutchings <ben@decadent.org.uk>2018-10-21 08:45:21 +0100
commitf3793cd7ef6d37f3f3eff2d05c3a4182f7d51871 (patch)
tree7ed4beda9d158b99ba02c6a7455c3cc1adbacdde
parentd79e2213f2839365d6fdb45195e0888ed5a8be26 (diff)
downloadlinux-stable-f3793cd7ef6d37f3f3eff2d05c3a4182f7d51871.tar.gz
linux-stable-f3793cd7ef6d37f3f3eff2d05c3a4182f7d51871.tar.bz2
linux-stable-f3793cd7ef6d37f3f3eff2d05c3a4182f7d51871.zip
fs/proc/proc_sysctl.c: fix potential page fault while unregistering sysctl table
commit a0b0d1c345d0317efe594df268feb5ccc99f651e upstream. proc_sys_link_fill_cache() does not take currently unregistering sysctl tables into account, which might result into a page fault in sysctl_follow_link() - add a check to fix it. This bug has been present since v3.4. Link: http://lkml.kernel.org/r/20180228013506.4915-1-danilokrummrich@dk-develop.de Fixes: 0e47c99d7fe25 ("sysctl: Replace root_list with links between sysctl_table_sets") Signed-off-by: Danilo Krummrich <danilokrummrich@dk-develop.de> Acked-by: Kees Cook <keescook@chromium.org> Reviewed-by: Andrew Morton <akpm@linux-foundation.org> Cc: "Luis R . Rodriguez" <mcgrof@kernel.org> Cc: "Eric W. Biederman" <ebiederm@xmission.com> Cc: Alexey Dobriyan <adobriyan@gmail.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
-rw-r--r--fs/proc/proc_sysctl.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/fs/proc/proc_sysctl.c b/fs/proc/proc_sysctl.c
index 75a00557cfea..bfb8e8d588b8 100644
--- a/fs/proc/proc_sysctl.c
+++ b/fs/proc/proc_sysctl.c
@@ -654,7 +654,10 @@ static bool proc_sys_link_fill_cache(struct file *file,
struct ctl_table *table)
{
bool ret = true;
+
head = sysctl_head_grab(head);
+ if (IS_ERR(head))
+ return false;
if (S_ISLNK(table->mode)) {
/* It is not an error if we can not follow the link ignore it */