Skip to content

Commit

Permalink
[PATCH] get rid of leak in compat_execve()
Browse files Browse the repository at this point in the history
Even though copy_compat_strings() doesn't cache the pages,
copy_strings_kernel() and stuff indirectly called by e.g.
->load_binary() is doing that, so we need to drop the
cache contents in the end.

[found by WANG Cong <[email protected]>]

Signed-off-by: Al Viro <[email protected]>
  • Loading branch information
Al Viro committed May 16, 2008
1 parent 5f71955 commit 08a6fac
Show file tree
Hide file tree
Showing 3 changed files with 11 additions and 6 deletions.
4 changes: 2 additions & 2 deletions fs/compat.c
Original file line number Diff line number Diff line change
Expand Up @@ -1405,7 +1405,7 @@ int compat_do_execve(char * filename,
/* execve success */
security_bprm_free(bprm);
acct_update_integrals(current);
kfree(bprm);
free_bprm(bprm);
return retval;
}

Expand All @@ -1424,7 +1424,7 @@ int compat_do_execve(char * filename,
}

out_kfree:
kfree(bprm);
free_bprm(bprm);

out_ret:
return retval;
Expand Down
12 changes: 8 additions & 4 deletions fs/exec.c
Original file line number Diff line number Diff line change
Expand Up @@ -1251,6 +1251,12 @@ int search_binary_handler(struct linux_binprm *bprm,struct pt_regs *regs)

EXPORT_SYMBOL(search_binary_handler);

void free_bprm(struct linux_binprm *bprm)
{
free_arg_pages(bprm);
kfree(bprm);
}

/*
* sys_execve() executes a new program.
*/
Expand Down Expand Up @@ -1320,17 +1326,15 @@ int do_execve(char * filename,
retval = search_binary_handler(bprm,regs);
if (retval >= 0) {
/* execve success */
free_arg_pages(bprm);
security_bprm_free(bprm);
acct_update_integrals(current);
kfree(bprm);
free_bprm(bprm);
if (displaced)
put_files_struct(displaced);
return retval;
}

out:
free_arg_pages(bprm);
if (bprm->security)
security_bprm_free(bprm);

Expand All @@ -1344,7 +1348,7 @@ int do_execve(char * filename,
fput(bprm->file);
}
out_kfree:
kfree(bprm);
free_bprm(bprm);

out_files:
if (displaced)
Expand Down
1 change: 1 addition & 0 deletions include/linux/binfmts.h
Original file line number Diff line number Diff line change
Expand Up @@ -99,6 +99,7 @@ extern int copy_strings_kernel(int argc,char ** argv,struct linux_binprm *bprm);
extern void compute_creds(struct linux_binprm *binprm);
extern int do_coredump(long signr, int exit_code, struct pt_regs * regs);
extern int set_binfmt(struct linux_binfmt *new);
extern void free_bprm(struct linux_binprm *);

#endif /* __KERNEL__ */
#endif /* _LINUX_BINFMTS_H */

0 comments on commit 08a6fac

Please sign in to comment.