md/raid1: fix a use-after-free bug
authorShaohua Li <shli@fb.com>
Mon, 20 Feb 2017 06:41:27 +0000 (22:41 -0800)
committerShaohua Li <shli@fb.com>
Mon, 20 Feb 2017 06:41:27 +0000 (22:41 -0800)
Commit fd76863 (RAID1: a new I/O barrier implementation to remove resync
window) introduces a user-after-free bug.

Signed-off-by: Shaohua Li <shli@fb.com>
drivers/md/raid1.c

index fefbbfdb440b4199ecd2a79fb90517df0693156c..2e5e4805cbe110bdfeaf7e75b8fe26376803d764 100644 (file)
@@ -203,6 +203,7 @@ static void free_r1bio(struct r1bio *r1_bio)
 static void put_buf(struct r1bio *r1_bio)
 {
        struct r1conf *conf = r1_bio->mddev->private;
+       sector_t sect = r1_bio->sector;
        int i;
 
        for (i = 0; i < conf->raid_disks * 2; i++) {
@@ -213,7 +214,7 @@ static void put_buf(struct r1bio *r1_bio)
 
        mempool_free(r1_bio, conf->r1buf_pool);
 
-       lower_barrier(conf, r1_bio->sector);
+       lower_barrier(conf, sect);
 }
 
 static void reschedule_retry(struct r1bio *r1_bio)