fuse: fix page dereference after free
authorMiklos Szeredi <mszeredi@redhat.com>
Fri, 18 Sep 2020 08:36:50 +0000 (10:36 +0200)
committerMiklos Szeredi <mszeredi@redhat.com>
Fri, 18 Sep 2020 08:36:50 +0000 (10:36 +0200)
commitd78092e4937de9ce55edcb4ee4c5e3c707be0190
tree6374d3ef13d8ee1b6e442b42447005f4e5d35c36
parent9a752d18c85ae5da28e4a07d52adfd95eacb2495
fuse: fix page dereference after free

After unlock_request() pages from the ap->pages[] array may be put (e.g. by
aborting the connection) and the pages can be freed.

Prevent use after free by grabbing a reference to the page before calling
unlock_request().

The original patch was created by Pradeep P V K.

Reported-by: Pradeep P V K <ppvk@codeaurora.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
fs/fuse/dev.c