diff options
author | Josef Bacik <josef@redhat.com> | 2010-11-19 15:41:10 +0100 |
---|---|---|
committer | Josef Bacik <josef@redhat.com> | 2010-12-09 19:57:10 +0100 |
commit | 955256f2c3e25c94ad373c43fbc38d2ac8af2a71 (patch) | |
tree | f8a6074a34e988e613eb308d4aeb91fd8fb2e968 /fs | |
parent | Btrfs: don't use migrate page without CONFIG_MIGRATION (diff) | |
download | linux-955256f2c3e25c94ad373c43fbc38d2ac8af2a71.tar.xz linux-955256f2c3e25c94ad373c43fbc38d2ac8af2a71.zip |
Btrfs: fix use after free in O_DIRECT
This fixes a bug where we use dip after we have freed it. Instead just use the
file_offset that was passed to the function. Thanks,
Signed-off-by: Josef Bacik <josef@redhat.com>
Diffstat (limited to 'fs')
-rw-r--r-- | fs/btrfs/inode.c | 3 |
1 files changed, 1 insertions, 2 deletions
diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c index 0f34cae0a633..ae6c0d190bc1 100644 --- a/fs/btrfs/inode.c +++ b/fs/btrfs/inode.c @@ -5934,8 +5934,7 @@ free_ordered: */ if (write) { struct btrfs_ordered_extent *ordered; - ordered = btrfs_lookup_ordered_extent(inode, - dip->logical_offset); + ordered = btrfs_lookup_ordered_extent(inode, file_offset); if (!test_bit(BTRFS_ORDERED_PREALLOC, &ordered->flags) && !test_bit(BTRFS_ORDERED_NOCOW, &ordered->flags)) btrfs_free_reserved_extent(root, ordered->start, |