[PATCH] NULL pointer dereference in ecryptfs (ecryptfs_setxattr)

From: Priya Bansal
Date: Wed Sep 24 2014 - 02:58:13 EST


This patch fixes the issue which was found in
ecryptfs_setxattr(). Previously, while trying to create a file when ecryptfs
is mounted over ext4 filesystem with encrypted view enabled, the kernel
crashes. the reason being the function fsstack_copy_attr_all was trying to
access dentry->d_inode which was null hence the kernel crashes with NULL
pointer dereference. Now a check has been applied which prevents such
condition.

From 74856445756aba18f98aa5b98ad46e7d98f54737 Mon Sep 17 00:00:00 2001
From: Priya Bansal <p.bansal@xxxxxxxxxxx>
Date: Fri, 29 Aug 2014 10:27:27 +0530
Subject: [PATCH] Fix in ecryptfs_setxattr for NULL check before calling
fsstack_copy_attr_all. This patch fixes the issue which was found in
ecryptfs_setxattr(). Previously, while trying to create a file when ecryptfs
is mounted over ext4 filesystem with encrypted view enabled, the kernel
crashes. the reason being the function fsstack_copy_attr_all was trying to
access dentry->d_inode which was null hence the kernel crashes with NULL
pointer dereference. Now a check has been applied which prevents such
condition.
Signed-off-by: Priya Bansal <p.bansal@xxxxxxxxxxx>
---
linux-3.16.1/fs/ecryptfs/inode.c | 18 ++++++++++++++++--
1 file changed, 16 insertions(+), 2 deletions(-)
diff --git a/linux-3.16.1/fs/ecryptfs/inode.c b/linux-3.16.1/fs/ecryptfs/inode.c
index d4a9431..7da03e5 100644
--- a/linux-3.16.1/fs/ecryptfs/inode.c
+++ b/linux-3.16.1/fs/ecryptfs/inode.c
@@ -1031,6 +1031,8 @@ ecryptfs_setxattr(struct dentry *dentry, const char *name, const void *value,
{
int rc = 0;
struct dentry *lower_dentry;
+ struct ecryptfs_mount_crypt_stat *mount_crypt_stat =
+ &ecryptfs_superblock_to_private(dentry->d_sb)->mount_crypt_stat;

lower_dentry = ecryptfs_dentry_to_lower(dentry);
if (!lower_dentry->d_inode->i_op->setxattr) {
@@ -1039,8 +1041,20 @@ ecryptfs_setxattr(struct dentry *dentry, const char *name, const void *value,
}

rc = vfs_setxattr(lower_dentry, name, value, size, flags);
- if (!rc)
- fsstack_copy_attr_all(dentry->d_inode, lower_dentry->d_inode);
+ if (!rc) {
+ if (dentry->d_inode == NULL) {
+ if (mount_crypt_stat->flags
+ & ECRYPTFS_ENCRYPTED_VIEW_ENABLED)
+ rc = -EPERM;
+ else if (mount_crypt_stat->flags
+ & ECRYPTFS_XATTR_METADATA_ENABLED)
+ goto out;
+ } else {
+ fsstack_copy_attr_all(dentry->d_inode,
+ lower_dentry->d_inode);
+ }
+ }
+
out:
return rc;
}
--
1.8.3.2

If you need any other details regarding this contribution, please contact me.

Thanks & Regards
Priya Bansal.
E-mail: p.bansal@xxxxxxxxxxx
N‹§²æìr¸›yúèšØb²X¬¶Ç§vØ^–)Þº{.nÇ+‰·¥Š{±‘êçzX§¶›¡Ü¨}©ž²Æ zÚ&j:+v‰¨¾«‘êçzZ+€Ê+zf£¢·hšˆ§~†­†Ûiÿûàz¹®w¥¢¸?™¨è­Ú&¢)ߢf”ù^jÇ«y§m…á@A«a¶Úÿ 0¶ìh®å’i