Files
android_kernel_samsung_msm8…/fs
Marc Zyngier d6e07ffd39 epoll: Keep a reference on files added to the check list
commit a9ed4a6560b8562b7e2e2bed9527e88001f7b682 upstream.

When adding a new fd to an epoll, and that this new fd is an
epoll fd itself, we recursively scan the fds attached to it
to detect cycles, and add non-epool files to a "check list"
that gets subsequently parsed.

However, this check list isn't completely safe when deletions
can happen concurrently. To sidestep the issue, make sure that
a struct file placed on the check list sees its f_count increased,
ensuring that a concurrent deletion won't result in the file
disapearing from under our feet.

Cc: stable@vger.kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I780923748a8387fa6b3174b952ca22994a377170
CVE-2020-0466
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-01-03 21:26:48 +01:00
..
2020-09-23 17:32:09 +02:00
2020-09-23 17:32:06 +02:00
2020-09-23 17:32:06 +02:00
…
2019-08-08 15:28:40 +02:00
2019-08-23 13:20:00 +02:00
2020-09-23 17:32:06 +02:00
2020-09-23 17:32:09 +02:00
2020-09-23 17:32:09 +02:00
2020-09-23 17:32:06 +02:00
…
2021-01-03 21:26:48 +01:00
2020-09-23 17:32:06 +02:00
2020-09-23 17:32:09 +02:00
2019-08-06 11:48:19 +02:00
2020-09-23 17:29:09 +02:00
2019-08-05 14:20:47 +02:00
2019-08-06 10:44:47 +02:00
…
2020-09-23 17:37:32 +02:00
2019-08-05 14:20:47 +02:00
2019-08-05 14:20:47 +02:00
…
2020-09-23 17:32:10 +02:00
2019-08-05 14:20:47 +02:00
2019-08-05 14:20:47 +02:00
2020-09-23 17:32:10 +02:00
…
…
2020-09-23 17:32:09 +02:00
2019-08-06 10:45:24 +02:00
…
…
2019-08-06 12:31:34 +02:00