diag: Protect the decrement of number of diag clients

In diagchar_open() protect the decrement of number of diag clients
so that there will be no race conditions while reading the value
from other functions.

Bug: 79421261
Change-Id: I0e2fb5331eec9c7bba39e7d881b69559256833a3
Signed-off-by: Sreelakshmi Gownipalli <sgownipa@codeaurora.org>
CVE-2018-5905
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
Sreelakshmi Gownipalli
2019-08-08 16:37:16 +02:00
committed by Francescodario Cuzzocrea
parent 5ab2a121fb
commit f4427b8ffe
+3 -2
View File
@@ -1,4 +1,5 @@
/* Copyright (c) 2008-2015, The Linux Foundation. All rights reserved.
/* Copyright (c) 2008-2015, 2017-2018 The Linux Foundation.
* All rights reserved.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 2 and
@@ -257,7 +258,7 @@ static int diagchar_open(struct inode *inode, struct file *file)
fail:
driver->num_clients--;
mutex_unlock(&driver->diagchar_mutex);
pr_alert("diag: Insufficient memory for new client");
pr_err_ratelimited("diag: Insufficient memory for new client");
return -ENOMEM;
}