Audit: fix audit watch use after free
authorEric Paris <eparis@redhat.com>
Thu, 11 Jun 2009 18:31:33 +0000 (14:31 -0400)
committerAl Viro <viro@zeniv.linux.org.uk>
Wed, 24 Jun 2009 03:50:33 +0000 (23:50 -0400)
When an audit watch is added to a parent the temporary watch inside the
original krule from userspace is freed.  Yet the original watch is used after
the real watch was created in audit_add_rules()

Signed-off-by: Eric Paris <eparis@redhat.com>
kernel/auditfilter.c

index 713098e..19c0a0a 100644 (file)
@@ -1320,6 +1320,8 @@ static inline int audit_add_rule(struct audit_entry *entry)
                        mutex_unlock(&audit_filter_mutex);
                        goto error;
                }
+               /* entry->rule.watch may have changed during audit_add_watch() */
+               watch = entry->rule.watch;
                h = audit_hash_ino((u32)watch->ino);
                list = &audit_inode_hash[h];
        }