ksmbd: fix possible refcount leak in smb2_open()
authorChenXiaoSong <chenxiaosong2@huawei.com>
Thu, 2 Mar 2023 13:58:04 +0000 (21:58 +0800)
committerSteve French <stfrench@microsoft.com>
Wed, 22 Mar 2023 21:38:33 +0000 (16:38 -0500)
Reference count of acls will leak when memory allocation fails. Fix this
by adding the missing posix_acl_release().

Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Signed-off-by: ChenXiaoSong <chenxiaosong2@huawei.com>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/ksmbd/smb2pdu.c

index cb779d2..97c9d1b 100644 (file)
@@ -2977,8 +2977,11 @@ int smb2_open(struct ksmbd_work *work)
                                                        sizeof(struct smb_acl) +
                                                        sizeof(struct smb_ace) * ace_num * 2,
                                                        GFP_KERNEL);
-                                       if (!pntsd)
+                                       if (!pntsd) {
+                                               posix_acl_release(fattr.cf_acls);
+                                               posix_acl_release(fattr.cf_dacls);
                                                goto err_out;
+                                       }
 
                                        rc = build_sec_desc(idmap,
                                                            pntsd, NULL, 0,