[PATCH V5] nfsd: fix nfsd4_create_reclaim_record_grace crp null-ptr-deref in nfs4recover

Lai Zewei <[email protected]>
Newsgroups gmane.linux.nfs,gmane.linux.kernel
Message-ID <[email protected]>
nfs4_client_to_reclaim() may return NULL if alloc_reclaim() fails. 
The caller __nfsd4_create_reclaim_record_grace() then unconditionally
dereferences the returned pointer via crp->cr_clp = clp, leading to a
null-ptr-deref crash.

Add a NULL check before assignment. If crp is NULL, just return.

Fixes: 4552f4e3f2c9 ("nfsd: change nfs4_client_to_reclaim() to allocate data")
Signed-off-by: Lai Zewei <[email protected]>
---
 fs/nfsd/nfs4recover.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/fs/nfsd/nfs4recover.c b/fs/nfsd/nfs4recover.c
index 6ea25a52d2f4..005e3990da99 100644
--- a/fs/nfsd/nfs4recover.c
+++ b/fs/nfsd/nfs4recover.c
@@ -116,7 +116,8 @@ __nfsd4_create_reclaim_record_grace(struct nfs4_client *clp,
 	struct nfs4_client_reclaim *crp;
 
 	crp = nfs4_client_to_reclaim(name, princhash, nn);
-	crp->cr_clp = clp;
+	if (crp)
+		crp->cr_clp = clp;
 }
 
 static void
-- 
2.52.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.