40 lines
1.1 KiB
Diff
40 lines
1.1 KiB
Diff
|
From 8d657eb3b43861064d36241e88d9d61c709f33f0 Mon Sep 17 00:00:00 2001
|
||
|
From: Dave Jones <davej@redhat.com>
|
||
|
Date: Fri, 13 Jul 2012 13:35:36 -0400
|
||
|
Subject: Remove easily user-triggerable BUG from generic_setlease
|
||
|
|
||
|
From: Dave Jones <davej@redhat.com>
|
||
|
|
||
|
commit 8d657eb3b43861064d36241e88d9d61c709f33f0 upstream.
|
||
|
|
||
|
This can be trivially triggered from userspace by passing in something unexpected.
|
||
|
|
||
|
kernel BUG at fs/locks.c:1468!
|
||
|
invalid opcode: 0000 [#1] SMP
|
||
|
RIP: 0010:generic_setlease+0xc2/0x100
|
||
|
Call Trace:
|
||
|
__vfs_setlease+0x35/0x40
|
||
|
fcntl_setlease+0x76/0x150
|
||
|
sys_fcntl+0x1c6/0x810
|
||
|
system_call_fastpath+0x1a/0x1f
|
||
|
|
||
|
Signed-off-by: Dave Jones <davej@redhat.com>
|
||
|
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||
|
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
||
|
|
||
|
---
|
||
|
fs/locks.c | 2 +-
|
||
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||
|
|
||
|
--- a/fs/locks.c
|
||
|
+++ b/fs/locks.c
|
||
|
@@ -1465,7 +1465,7 @@ int generic_setlease(struct file *filp,
|
||
|
case F_WRLCK:
|
||
|
return generic_add_lease(filp, arg, flp);
|
||
|
default:
|
||
|
- BUG();
|
||
|
+ return -EINVAL;
|
||
|
}
|
||
|
}
|
||
|
EXPORT_SYMBOL(generic_setlease);
|