summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDavid Disseldorp <ddiss@suse.de>2017-05-03 17:39:08 +0200
committerSteve French <smfrench@gmail.com>2017-05-03 16:59:20 +0200
commit6026685de33b0db5b2b6b0e9b41b3a1a3261033c (patch)
tree01c0c2fcf7cc95eb8c29b3664e54addf146a5987
parentcifs: fix leak in FSCTL_ENUM_SNAPS response handling (diff)
downloadlinux-6026685de33b0db5b2b6b0e9b41b3a1a3261033c.tar.xz
linux-6026685de33b0db5b2b6b0e9b41b3a1a3261033c.zip
cifs: fix CIFS_ENUMERATE_SNAPSHOTS oops
As with 618763958b22, an open directory may have a NULL private_data pointer prior to readdir. CIFS_ENUMERATE_SNAPSHOTS must check for this before dereference. Fixes: 834170c85978 ("Enable previous version support") Signed-off-by: David Disseldorp <ddiss@suse.de> CC: Stable <stable@vger.kernel.org> Signed-off-by: Steve French <smfrench@gmail.com>
-rw-r--r--fs/cifs/ioctl.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/fs/cifs/ioctl.c b/fs/cifs/ioctl.c
index 7f4bba574930..4d598a71cf84 100644
--- a/fs/cifs/ioctl.c
+++ b/fs/cifs/ioctl.c
@@ -213,6 +213,8 @@ long cifs_ioctl(struct file *filep, unsigned int command, unsigned long arg)
rc = smb_mnt_get_fsinfo(xid, tcon, (void __user *)arg);
break;
case CIFS_ENUMERATE_SNAPSHOTS:
+ if (pSMBFile == NULL)
+ break;
if (arg == 0) {
rc = -EINVAL;
goto cifs_ioc_exit;