From: Alan Cox Date: Fri, 9 Nov 2012 03:04:55 +0000 (+1100) Subject: binfmt_elf: fix corner case kfree of uninitialized data X-Git-Tag: next-20121112~5^2~78 X-Git-Url: https://git.karo-electronics.de/?a=commitdiff_plain;h=d6ca94d46c7c5b47fc6eef001cb766aa03c34f1c;p=karo-tx-linux.git binfmt_elf: fix corner case kfree of uninitialized data If elf_core_dump() is called and fill_note_info() fails in the kmalloc() then it returns 0 but has not yet initialised all the needed fields. As a result we do a kfree(randomness) after correctly skipping the thread data. Signed-off-by: Alan Cox Signed-off-by: Andrew Morton --- diff --git a/fs/binfmt_elf.c b/fs/binfmt_elf.c index 6d7d1647a68c..1dc9b185e33d 100644 --- a/fs/binfmt_elf.c +++ b/fs/binfmt_elf.c @@ -1601,8 +1601,10 @@ static int fill_note_info(struct elfhdr *elf, int phdrs, info->thread = NULL; psinfo = kmalloc(sizeof(*psinfo), GFP_KERNEL); - if (psinfo == NULL) + if (psinfo == NULL) { + info->psinfo.data = NULL; /* So we don't free this wrongly */ return 0; + } fill_note(&info->psinfo, "CORE", NT_PRPSINFO, sizeof(*psinfo), psinfo);