Message ID | e3f2929bbfacac5ad5b02cf3de39ecd5e6287e40.1493839103.git.osandov@fb.com (mailing list archive) |
---|---|
State | New, archived |
Headers | show |
diff --git a/block/blk-mq-debugfs.c b/block/blk-mq-debugfs.c index 00cc89c34590..48b9f59acd91 100644 --- a/block/blk-mq-debugfs.c +++ b/block/blk-mq-debugfs.c @@ -102,6 +102,14 @@ static ssize_t queue_state_write(void *data, const char __user *buf, struct request_queue *q = data; char op[16] = { }, *s; + /* + * The "state" attribute is removed after blk_cleanup_queue() has called + * blk_mq_free_queue(). Return if QUEUE_FLAG_DEAD has been set to avoid + * triggering a use-after-free. + */ + if (blk_queue_dead(q)) + return -ENOENT; + if (copy_from_user(op, buf, min(count, sizeof(op) - 1))) return -EFAULT; s = op;