Thread (4 messages) 4 messages, 4 authors, 2018-07-30

Re: [PATCH] block: blk_init_allocated_queue() set q->fq as NULL in the fail case

From: Bart Van Assche <hidden>
Date: 2018-07-30 13:42:19
Also in: lkml, stable

On Mon, 2018-07-30 at 14:11 +0800, xiao jin wrote:
We find the memory use-after-free issue in __blk_drain_=
queue()
on the kernel 4.14. After read the latest kernel 4.18-rc6 we
think it has the same problem.
=20
Memory is allocated for q->fq in the blk_init_allocated�
F8-queue().
If the elevator init function called with error return, it will
run into the fail case to free the q->fq.
=20
Then the __blk_drain_queue() uses the same memory after=
 the free
of the q->fq, it will lead to the unpredictable event.
=20
The patch is to set q->fq as NULL in the fail case of
blk_init_allocated_queue().
Reviewed-by: Bart Van Assche <redacted>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help