Skip to content
This repository was archived by the owner on Oct 31, 2024. It is now read-only.

Commit d52c565

Browse files
Lizhi Xugregkh
Lizhi Xu
authored andcommittedOct 10, 2024
ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
commit 33b525c upstream. When doing cleanup, if flags without OCFS2_BH_READAHEAD, it may trigger NULL pointer dereference in the following ocfs2_set_buffer_uptodate() if bh is NULL. Link: https://lkml.kernel.org/r/20240902023636.1843422-3-joseph.qi@linux.alibaba.com Fixes: cf76c78 ("ocfs2: don't put and assigning null to bh allocated outside") Signed-off-by: Lizhi Xu <lizhi.xu@windriver.com> Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com> Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com> Reported-by: Heming Zhao <heming.zhao@suse.com> Suggested-by: Heming Zhao <heming.zhao@suse.com> Cc: <stable@vger.kernel.org> [4.20+] Cc: Changwei Ge <gechangwei@live.cn> Cc: Gang He <ghe@suse.com> Cc: Joel Becker <jlbec@evilplan.org> Cc: Jun Piao <piaojun@huawei.com> Cc: Junxiao Bi <junxiao.bi@oracle.com> Cc: Mark Fasheh <mark@fasheh.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 86a89e7 commit d52c565

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed
 

‎fs/ocfs2/buffer_head_io.c

+2-1
Original file line numberDiff line numberDiff line change
@@ -388,7 +388,8 @@ int ocfs2_read_blocks(struct ocfs2_caching_info *ci, u64 block, int nr,
388388
/* Always set the buffer in the cache, even if it was
389389
* a forced read, or read-ahead which hasn't yet
390390
* completed. */
391-
ocfs2_set_buffer_uptodate(ci, bh);
391+
if (bh)
392+
ocfs2_set_buffer_uptodate(ci, bh);
392393
}
393394
ocfs2_metadata_cache_io_unlock(ci);
394395

0 commit comments

Comments
 (0)
This repository has been archived.