On Thu, 28 Sep 2017, Eric Biggers wrote:

> From: Eric Biggers <[email protected]>
> 
> When the file /proc/fs/fscache/objects (available with
> CONFIG_FSCACHE_OBJECT_LIST=y) is opened, we request a user key with
> description "fscache:objlist", then access its payload.  However, a
> revoked key has a NULL payload, and we failed to check for this.
> request_key() *does* skip revoked keys, but there is still a window
> where the key can be revoked before we access its payload.
> 
> Fix it by checking for a NULL payload, treating it like a key which was
> already revoked at the time it was requested.
> 
> Fixes: 4fbf4291aa15 ("FS-Cache: Allow the current state of all objects to be 
> dumped")
> Cc: <[email protected]>    [v2.6.32+]
> Signed-off-by: Eric Biggers <[email protected]>


Reviewed-by: James Morris <[email protected]>


-- 
James Morris
<[email protected]>

--
Linux-cachefs mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/linux-cachefs

Reply via email to