diff options
author | Liu ShuoX <shuox.liu@intel.com> | 2014-03-17 21:57:49 +0100 |
---|---|---|
committer | Tony Luck <tony.luck@intel.com> | 2014-03-17 22:14:03 +0100 |
commit | b0aa931fb84431394d995472d0af2a6c2b61064d (patch) | |
tree | dc51c08fc851d57745ebc79851a9622d7e8b4d15 | |
parent | pstore: skip zero size persistent ram buffer in traverse (diff) | |
download | linux-b0aa931fb84431394d995472d0af2a6c2b61064d.tar.xz linux-b0aa931fb84431394d995472d0af2a6c2b61064d.zip |
pstore: Fix NULL pointer fault if get NULL prz in ramoops_get_next_prz
ramoops_get_next_prz get the prz according the paramters. If it get a
uninitialized prz, access its members by following persistent_ram_old_size(prz)
will cause a NULL pointer crash.
Ex: if ftrace_size is 0, fprz will be NULL.
Fix it by return NULL in advance.
Signed-off-by: Liu ShuoX <shuox.liu@intel.com>
Acked-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Tony Luck <tony.luck@intel.com>
-rw-r--r-- | fs/pstore/ram.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/fs/pstore/ram.c b/fs/pstore/ram.c index 1daed280f1b6..6f96d8c2a711 100644 --- a/fs/pstore/ram.c +++ b/fs/pstore/ram.c @@ -119,6 +119,8 @@ ramoops_get_next_prz(struct persistent_ram_zone *przs[], uint *c, uint max, return NULL; prz = przs[i]; + if (!prz) + return NULL; /* Update old/shadowed buffer. */ if (update) |