[PATCH v3] ipc/shm: check shm_lock() in do_shmat cleanup
From: Yi Xie
Date: Thu Jul 16 2026 - 03:58:08 EST
do_shmat() calls shm_lock() in the out_nattch branch and
immediately dereferences it, however shm_lock() can return an
error.
Check for an error and handle it if there is one.
Signed-off-by: Yi Xie <xieyi@xxxxxxxxxx>
---
ipc/shm.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/ipc/shm.c b/ipc/shm.c
index b3e8a58e177d..d243137c4dbd 100644
--- a/ipc/shm.c
+++ b/ipc/shm.c
@@ -1677,12 +1677,16 @@ long do_shmat(int shmid, char __user *shmaddr, int shmflg,
out_nattch:
down_write(&shm_ids(ns).rwsem);
shp = shm_lock(ns, shmid);
- shp->shm_nattch--;
+ if (IS_ERR(shp)) {
+ err = PTR_ERR(shp);
+ } else {
+ shp->shm_nattch--;
- if (shm_may_destroy(shp))
- shm_destroy(ns, shp);
- else
- shm_unlock(shp);
+ if (shm_may_destroy(shp))
+ shm_destroy(ns, shp);
+ else
+ shm_unlock(shp);
+ }
up_write(&shm_ids(ns).rwsem);
return err;
--
2.25.1