| From: Al Viro <viro@zeniv.linux.org.uk> |
| Date: Tue, 3 Apr 2018 01:15:46 -0400 |
| Subject: rpc_pipefs: fix double-dput() |
| |
| commit 4a3877c4cedd95543f8726b0a98743ed8db0c0fb upstream. |
| |
| if we ever hit rpc_gssd_dummy_depopulate() dentry passed to |
| it has refcount equal to 1. __rpc_rmpipe() drops it and |
| dput() done after that hits an already freed dentry. |
| |
| Signed-off-by: Al Viro <viro@zeniv.linux.org.uk> |
| [bwh: Backported to 3.16: adjust context] |
| Signed-off-by: Ben Hutchings <ben@decadent.org.uk> |
| --- |
| net/sunrpc/rpc_pipe.c | 1 + |
| 1 file changed, 1 insertion(+) |
| |
| --- a/net/sunrpc/rpc_pipe.c |
| +++ b/net/sunrpc/rpc_pipe.c |
| @@ -1375,6 +1375,7 @@ rpc_gssd_dummy_depopulate(struct dentry |
| struct dentry *clnt_dir = pipe_dentry->d_parent; |
| struct dentry *gssd_dir = clnt_dir->d_parent; |
| |
| + dget(pipe_dentry); |
| __rpc_rmpipe(clnt_dir->d_inode, pipe_dentry); |
| __rpc_depopulate(clnt_dir, gssd_dummy_info_file, 0, 1); |
| __rpc_depopulate(gssd_dir, gssd_dummy_clnt_dir, 0, 1); |