xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing)
authorCathy Avery <cathy.avery@oracle.com>
Fri, 2 Oct 2015 13:35:01 +0000 (09:35 -0400)
committerKonrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Wed, 7 Oct 2015 19:15:18 +0000 (15:15 -0400)
xen-blkfront will crash if the check to talk_to_blkback()
in blkback_changed()(XenbusStateInitWait) returns an error.
The driver data is freed and info is set to NULL. Later during
the close process via talk_to_blkback's call to xenbus_dev_fatal()
the null pointer is passed to and dereference in blkfront_closing.

CC: stable@vger.kernel.org
Signed-off-by: Cathy Avery <cathy.avery@oracle.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
drivers/block/xen-blkfront.c

index 6d89ed35d80c0caaf8bf57ba82c7e9f3a9194bb9..c8fdbc77f9b1774c259f62b82ba2e03b302001d7 100644 (file)
@@ -1968,7 +1968,8 @@ static void blkback_changed(struct xenbus_device *dev,
                        break;
                /* Missed the backend's Closing state -- fallthrough */
        case XenbusStateClosing:
-               blkfront_closing(info);
+               if (info)
+                       blkfront_closing(info);
                break;
        }
 }