summaryrefslogtreecommitdiffstats
path: root/fs/cifs
diff options
context:
space:
mode:
authorColin Ian King <colin.king@canonical.com>2020-07-31 19:13:42 +0200
committerSteve French <stfrench@microsoft.com>2020-08-03 01:00:26 +0200
commitc6a80e1ff4106755b8e72a88e767deb7c9d45050 (patch)
tree9ccdbb0b59465c7626f53f5b2062744e6dc4ea35 /fs/cifs
parentcifs: handle RESP_GET_DFS_REFERRAL.PathConsumed in reconnect (diff)
downloadlinux-c6a80e1ff4106755b8e72a88e767deb7c9d45050.tar.xz
linux-c6a80e1ff4106755b8e72a88e767deb7c9d45050.zip
cifs: fix double free error on share and prefix
Currently if the call dfs_cache_get_tgt_share fails we cannot fully guarantee that share and prefix are set to NULL and the next iteration of the loop can end up potentially double freeing these pointers. Since the semantics of dfs_cache_get_tgt_share are ambiguous for failure cases with the setting of share and prefix (currently now and the possibly the future), it seems prudent to set the pointers to NULL when the objects are free'd to avoid any double frees. Addresses-Coverity: ("Double free") Fixes: 96296c946a2a ("cifs: handle RESP_GET_DFS_REFERRAL.PathConsumed in reconnect") Signed-off-by: Colin Ian King <colin.king@canonical.com> Signed-off-by: Steve French <stfrench@microsoft.com> Reviewed-by: Paulo Alcantara (SUSE) <pc@cjr.nz>
Diffstat (limited to 'fs/cifs')
-rw-r--r--fs/cifs/connect.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c
index 48b5133580d5..aae90953e07f 100644
--- a/fs/cifs/connect.c
+++ b/fs/cifs/connect.c
@@ -5574,6 +5574,8 @@ int cifs_tree_connect(const unsigned int xid, struct cifs_tcon *tcon, const stru
kfree(share);
kfree(prefix);
+ share = NULL;
+ prefix = NULL;
rc = dfs_cache_get_tgt_share(tcon->dfs_path + 1, it, &share, &prefix);
if (rc) {