[PATCH v3] ipc/shm: check shm_lock() in do_shmat cleanup

From: Yi Xie

Date: Thu Jul 16 2026 - 03:58:08 EST


do_shmat() calls shm_lock() in the out_nattch branch and
immediately dereferences it, however shm_lock() can return an
error.

Check for an error and handle it if there is one.

Signed-off-by: Yi Xie <xieyi@xxxxxxxxxx>
---
ipc/shm.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)

diff --git a/ipc/shm.c b/ipc/shm.c
index b3e8a58e177d..d243137c4dbd 100644
--- a/ipc/shm.c
+++ b/ipc/shm.c
@@ -1677,12 +1677,16 @@ long do_shmat(int shmid, char __user *shmaddr, int shmflg,
out_nattch:
down_write(&shm_ids(ns).rwsem);
shp = shm_lock(ns, shmid);
- shp->shm_nattch--;
+ if (IS_ERR(shp)) {
+ err = PTR_ERR(shp);
+ } else {
+ shp->shm_nattch--;

- if (shm_may_destroy(shp))
- shm_destroy(ns, shp);
- else
- shm_unlock(shp);
+ if (shm_may_destroy(shp))
+ shm_destroy(ns, shp);
+ else
+ shm_unlock(shp);
+ }
up_write(&shm_ids(ns).rwsem);
return err;

--
2.25.1