pty: fix possible use after free of tty->driver_data
authorHerton R. Krzesinski <herton@redhat.com>
Mon, 11 Jan 2016 14:07:43 +0000 (12:07 -0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 25 Feb 2016 19:57:46 +0000 (11:57 -0800)
commit042105bb8df0b22c4cd5867f15cfdd0048326f86
treeb16fc0769c0a6fce2e404fc4c9c48f089c3d55f2
parentd2878b36ad382cb3184e37737b6d7f24162321f8
pty: fix possible use after free of tty->driver_data

commit 2831c89f42dcde440cfdccb9fee9f42d54bbc1ef upstream.

This change fixes a bug for a corner case where we have the the last
release from a pty master/slave coming from a previously opened /dev/tty
file. When this happens, the tty->driver_data can be stale, due to all
ptmx or pts/N files having already been closed before (and thus the inode
related to these files, which tty->driver_data points to, being already
freed/destroyed).

The fix here is to keep a reference on the opened master ptmx inode.
We maintain the inode referenced until the final pty_unix98_shutdown,
and only pass this inode to devpts_kill_index.

Signed-off-by: Herton R. Krzesinski <herton@redhat.com>
Reviewed-by: Peter Hurley <peter@hurleysoftware.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/tty/pty.c