[LU-7078] use after free from ll_update_lsm_md() Created: 01/Sep/15 Updated: 19/Sep/15 Resolved: 19/Sep/15 |
|
| Status: | Resolved |
| Project: | Lustre |
| Component/s: | None |
| Affects Version/s: | Lustre 2.8.0 |
| Fix Version/s: | Lustre 2.8.0 |
| Type: | Bug | Priority: | Minor |
| Reporter: | John Hammond | Assignee: | Di Wang |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | None | ||
| Issue Links: |
|
||||
| Severity: | 3 | ||||
| Rank (Obsolete): | 9223372036854775807 | ||||
| Description |
|
In ll_update_lmd_md() if md_merge_attr() fails then the lmv_stripe_md is pointed to by both lli->lli_lsm_md and md->lmv. After the failure the stripe md is freed by md_free_lustre_md() and so lli->lli_lsm_md becomes a dangling pointer. |
| Comments |
| Comment by Gerrit Updater [ 11/Sep/15 ] |
|
wangdi (di.wang@intel.com) uploaded a new patch: http://review.whamcloud.com/16382 |
| Comment by Gerrit Updater [ 19/Sep/15 ] |
|
Oleg Drokin (oleg.drokin@intel.com) merged in patch http://review.whamcloud.com/16382/ |
| Comment by Peter Jones [ 19/Sep/15 ] |
|
Landed for 2.8 |