fs: NULL dereference in posix_acl_to_xattr()
commit 47ba973440
upstream.
This patch moves the dereference of "buffer" after the check for NULL.
The only place which passes a NULL parameter is gfs2_set_acl().
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Steven Whitehouse <swhiteho@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
c80e9ae4c5
commit
d4654552f7
|
@ -723,7 +723,7 @@ posix_acl_to_xattr(struct user_namespace *user_ns, const struct posix_acl *acl,
|
||||||
void *buffer, size_t size)
|
void *buffer, size_t size)
|
||||||
{
|
{
|
||||||
posix_acl_xattr_header *ext_acl = (posix_acl_xattr_header *)buffer;
|
posix_acl_xattr_header *ext_acl = (posix_acl_xattr_header *)buffer;
|
||||||
posix_acl_xattr_entry *ext_entry = ext_acl->a_entries;
|
posix_acl_xattr_entry *ext_entry;
|
||||||
int real_size, n;
|
int real_size, n;
|
||||||
|
|
||||||
real_size = posix_acl_xattr_size(acl->a_count);
|
real_size = posix_acl_xattr_size(acl->a_count);
|
||||||
|
@ -731,7 +731,8 @@ posix_acl_to_xattr(struct user_namespace *user_ns, const struct posix_acl *acl,
|
||||||
return real_size;
|
return real_size;
|
||||||
if (real_size > size)
|
if (real_size > size)
|
||||||
return -ERANGE;
|
return -ERANGE;
|
||||||
|
|
||||||
|
ext_entry = ext_acl->a_entries;
|
||||||
ext_acl->a_version = cpu_to_le32(POSIX_ACL_XATTR_VERSION);
|
ext_acl->a_version = cpu_to_le32(POSIX_ACL_XATTR_VERSION);
|
||||||
|
|
||||||
for (n=0; n < acl->a_count; n++, ext_entry++) {
|
for (n=0; n < acl->a_count; n++, ext_entry++) {
|
||||||
|
|
Loading…
Reference in New Issue