pty: fix possible use after free of tty->driver_data
authorHerton R. Krzesinski <herton@redhat.com>
Mon, 11 Jan 2016 14:07:43 +0000 (12:07 -0200)
committerSasha Levin <sasha.levin@oracle.com>
Sun, 28 Feb 2016 05:09:49 +0000 (00:09 -0500)
commit614f8734d11ad22ee17a5faecf355b70756904ef
tree2f1660d0d61919078ca4d155a6e9b17c7fc9fab2
parent6ca45550112e975be2298b0feda49b686029cc32
pty: fix possible use after free of tty->driver_data

[ Upstream commit 2831c89f42dcde440cfdccb9fee9f42d54bbc1ef ]

This change fixes a bug for a corner case where we have the the last
release from a pty master/slave coming from a previously opened /dev/tty
file. When this happens, the tty->driver_data can be stale, due to all
ptmx or pts/N files having already been closed before (and thus the inode
related to these files, which tty->driver_data points to, being already
freed/destroyed).

The fix here is to keep a reference on the opened master ptmx inode.
We maintain the inode referenced until the final pty_unix98_shutdown,
and only pass this inode to devpts_kill_index.

Signed-off-by: Herton R. Krzesinski <herton@redhat.com>
Cc: <stable@vger.kernel.org> # 2.6.29+
Reviewed-by: Peter Hurley <peter@hurleysoftware.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
drivers/tty/pty.c