futex: Test for pi_mutex on fault in futex_wait_requeue_pi()
authorDarren Hart <dvhart@linux.intel.com>
Fri, 20 Jul 2012 18:53:29 +0000 (11:53 -0700)
committerThomas Gleixner <tglx@linutronix.de>
Tue, 24 Jul 2012 14:02:56 +0000 (16:02 +0200)
If fixup_pi_state_owner() faults, pi_mutex may be NULL. Test
for pi_mutex != NULL before testing the owner against current
and possibly unlocking it.

Signed-off-by: Darren Hart <dvhart@linux.intel.com>
Cc: Dave Jones <davej@redhat.com>
Cc: Dan Carpenter <dan.carpenter@oracle.com>
Cc: stable@vger.kernel.org
Link: http://lkml.kernel.org/r/dc59890338fc413606f04e5c5b131530734dae3d.1342809673.git.dvhart@linux.intel.com
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
kernel/futex.c

index e2b0fb9a0b3b3d0d5871ee37bf08618a6bf052e7..05018bfe21a7e6277656677ace6141e7a3effa34 100644 (file)
@@ -2370,7 +2370,7 @@ static int futex_wait_requeue_pi(u32 __user *uaddr, unsigned int flags,
         * fault, unlock the rt_mutex and return the fault to userspace.
         */
        if (ret == -EFAULT) {
-               if (rt_mutex_owner(pi_mutex) == current)
+               if (pi_mutex && rt_mutex_owner(pi_mutex) == current)
                        rt_mutex_unlock(pi_mutex);
        } else if (ret == -EINTR) {
                /*