aboutsummaryrefslogtreecommitdiffstats
path: root/kernel
diff options
context:
space:
mode:
authorPeter Zijlstra <peterz@infradead.org>2016-01-27 15:59:04 -0500
committerIngo Molnar <mingo@kernel.org>2016-01-29 02:35:24 -0500
commit828b6f0e26170938d617e99a17177453be4d77a3 (patch)
treea2e8b41d38805adf84d906bfca4d959d84ba6bee /kernel
parent8f04b8536f0c94f8999b65cd1c6c7523116a00ae (diff)
perf: Fix NULL deref
Dan reported: 1229 if (ctx->task == TASK_TOMBSTONE || 1230 !atomic_inc_not_zero(&ctx->refcount)) { 1231 raw_spin_unlock(&ctx->lock); 1232 ctx = NULL; ^^^^^^^^^^ ctx is NULL. 1233 } 1234 1235 WARN_ON_ONCE(ctx->task != task); ^^^^^^^^^^^^^^^^^ The patch adds a NULL dereference. Reported-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Cc: Arnaldo Carvalho de Melo <acme@redhat.com> Cc: David Ahern <dsahern@gmail.com> Cc: Jiri Olsa <jolsa@redhat.com> Cc: Linus Torvalds <torvalds@linux-foundation.org> Cc: Namhyung Kim <namhyung@kernel.org> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Stephane Eranian <eranian@google.com> Cc: Thomas Gleixner <tglx@linutronix.de> Cc: Vince Weaver <vincent.weaver@maine.edu> Fixes: 63b6da39bb38 ("perf: Fix perf_event_exit_task() race") Signed-off-by: Ingo Molnar <mingo@kernel.org>
Diffstat (limited to 'kernel')
-rw-r--r--kernel/events/core.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/kernel/events/core.c b/kernel/events/core.c
index 1d243fadfd12..fe97f95f204e 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -1230,9 +1230,9 @@ retry:
1230 !atomic_inc_not_zero(&ctx->refcount)) { 1230 !atomic_inc_not_zero(&ctx->refcount)) {
1231 raw_spin_unlock(&ctx->lock); 1231 raw_spin_unlock(&ctx->lock);
1232 ctx = NULL; 1232 ctx = NULL;
1233 } else {
1234 WARN_ON_ONCE(ctx->task != task);
1233 } 1235 }
1234
1235 WARN_ON_ONCE(ctx->task != task);
1236 } 1236 }
1237 rcu_read_unlock(); 1237 rcu_read_unlock();
1238 if (!ctx) 1238 if (!ctx)