[PATCH][ksmbd] fix UAF in ksmbd_alloc_work_struct

Nathan French posted 1 patch 2 years, 3 months ago
fs/smb/server/ksmbd_work.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH][ksmbd] fix UAF in ksmbd_alloc_work_struct
Posted by Nathan French 2 years, 3 months ago
    avoid oops accessing null work struct pointer

    Fixes: bdf1b0e2a1ea ("ksmbd_alloc_work_struct")
    Addresses-Coverity: 1566875 ("Explicit null dereference")
    Reviewed-by: Jackson Winslow <jackwinslow35@gmail.com>
    Signed-off-by: Nathan French <nathanmfrench17@gmail.com>

diff --git a/fs/smb/server/ksmbd_work.c b/fs/smb/server/ksmbd_work.c
index 51def3ca74c0..9411f7e32a3c 100644
--- a/fs/smb/server/ksmbd_work.c
+++ b/fs/smb/server/ksmbd_work.c
@@ -33,7 +33,7 @@ struct ksmbd_work *ksmbd_alloc_work_struct(void)
                                    GFP_KERNEL);
                if (!work->iov) {
                        kmem_cache_free(work_cache, work);
-                       work = NULL;
+                       return NULL;
                }
        }
        return work;
From c13817441c860fec14cc9d433719b83ca7de1ed0 Mon Sep 17 00:00:00 2001
From: Nathan French <nathanmfrench17@gmail.com>
Date: Mon, 21 Aug 2021 02:17:04 +0000
Subject: [PATCH] ksmbd: fix UAF in ksmbd_alloc_work_struct

avoid oops accessing null work struct pointer

Fixes: bdf1b0e2a1ea ("ksmbd_alloc_work_struct")
Addresses-Coverity: 1566875 ("Explicit null dereference")
Reviewed-by: Jackson Winslow <jackwinslow35@gmail.com>
Signed-off-by: Nathan French <nathanmfrench17@gmail.com>
---
 fs/smb/server/ksmbd_work.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/smb/server/ksmbd_work.c b/fs/smb/server/ksmbd_work.c
index 51def3ca74c0..9411f7e32a3c 100644
--- a/fs/smb/server/ksmbd_work.c
+++ b/fs/smb/server/ksmbd_work.c
@@ -33,7 +33,7 @@ struct ksmbd_work *ksmbd_alloc_work_struct(void)
 				    GFP_KERNEL);
 		if (!work->iov) {
 			kmem_cache_free(work_cache, work);
-			work = NULL;
+			return NULL;
 		}
 	}
 	return work;
-- 
2.39.2