| From 7913690dcc5e18e235769fd87c34143072f5dbea Mon Sep 17 00:00:00 2001 |
| From: Tomas Bortoli <tomasbortoli@gmail.com> |
| Date: Tue, 10 Jul 2018 00:29:43 +0200 |
| Subject: net/9p/client.c: version pointer uninitialized |
| |
| From: Tomas Bortoli <tomasbortoli@gmail.com> |
| |
| commit 7913690dcc5e18e235769fd87c34143072f5dbea upstream. |
| |
| The p9_client_version() does not initialize the version pointer. If the |
| call to p9pdu_readf() returns an error and version has not been allocated |
| in p9pdu_readf(), then the program will jump to the "error" label and will |
| try to free the version pointer. If version is not initialized, free() |
| will be called with uninitialized, garbage data and will provoke a crash. |
| |
| Link: http://lkml.kernel.org/r/20180709222943.19503-1-tomasbortoli@gmail.com |
| Signed-off-by: Tomas Bortoli <tomasbortoli@gmail.com> |
| Reported-by: syzbot+65c6b72f284a39d416b4@syzkaller.appspotmail.com |
| Reviewed-by: Jun Piao <piaojun@huawei.com> |
| Reviewed-by: Yiwen Jiang <jiangyiwen@huawei.com> |
| Cc: Eric Van Hensbergen <ericvh@gmail.com> |
| Cc: Ron Minnich <rminnich@sandia.gov> |
| Cc: Latchesar Ionkov <lucho@ionkov.net> |
| Signed-off-by: Andrew Morton <akpm@linux-foundation.org> |
| Cc: stable@vger.kernel.org |
| Signed-off-by: Dominique Martinet <dominique.martinet@cea.fr> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| net/9p/client.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| --- a/net/9p/client.c |
| +++ b/net/9p/client.c |
| @@ -931,7 +931,7 @@ static int p9_client_version(struct p9_c |
| { |
| int err = 0; |
| struct p9_req_t *req; |
| - char *version; |
| + char *version = NULL; |
| int msize; |
| |
| p9_debug(P9_DEBUG_9P, ">>> TVERSION msize %d protocol %d\n", |