]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
iscsi-target: Fix memory corruption in iscsit_logout_post_handler_diffcid
authorNicholas Bellinger <nab@linux-iscsi.org>
Wed, 17 Sep 2014 18:45:17 +0000 (11:45 -0700)
committerZefan Li <lizefan@huawei.com>
Mon, 1 Dec 2014 10:02:33 +0000 (18:02 +0800)
commit b53b0d99d6fbf7d44330395349a895521cfdbc96 upstream.

This patch fixes a bug in iscsit_logout_post_handler_diffcid() where
a pointer used as storage for list_for_each_entry() was incorrectly
being used to determine if no matching entry had been found.

This patch changes iscsit_logout_post_handler_diffcid() to key off
bool conn_found to determine if the function needs to exit early.

Reported-by: Joern Engel <joern@logfs.org>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Zefan Li <lizefan@huawei.com>
drivers/target/iscsi/iscsi_target.c

index d7ac2c095cc95d7ca3e284b1a395992cf32c26f3..56d02e071d7a0dd5801a017a2a8921f27a73c71c 100644 (file)
@@ -4297,6 +4297,7 @@ static void iscsit_logout_post_handler_diffcid(
 {
        struct iscsi_conn *l_conn;
        struct iscsi_session *sess = conn->sess;
+       bool conn_found = false;
 
        if (!sess)
                return;
@@ -4305,12 +4306,13 @@ static void iscsit_logout_post_handler_diffcid(
        list_for_each_entry(l_conn, &sess->sess_conn_list, conn_list) {
                if (l_conn->cid == cid) {
                        iscsit_inc_conn_usage_count(l_conn);
+                       conn_found = true;
                        break;
                }
        }
        spin_unlock_bh(&sess->conn_lock);
 
-       if (!l_conn)
+       if (!conn_found)
                return;
 
        if (l_conn->sock)