• Roberto Sassu's avatar
    ima: Directly free *entry in ima_alloc_init_template() if digests is NULL · 42413b49
    Roberto Sassu authored
    To support multiple template digests, the static array entry->digest has
    been replaced with a dynamically allocated array in commit aa724fe1
    ("ima: Switch to dynamically allocated buffer for template digests"). The
    array is allocated in ima_alloc_init_template() and if the returned pointer
    is NULL, ima_free_template_entry() is called.
    
    However, (*entry)->template_desc is not yet initialized while it is used by
    ima_free_template_entry(). This patch fixes the issue by directly freeing
    *entry without calling ima_free_template_entry().
    
    Fixes: aa724fe1 ("ima: Switch to dynamically allocated buffer for template digests")
    Reported-by: syzbot+223310b454ba6b75974e@syzkaller.appspotmail.com
    Signed-off-by: default avatarRoberto Sassu <roberto.sassu@huawei.com>
    Signed-off-by: default avatarMimi Zohar <zohar@linux.ibm.com>
    42413b49
ima_api.c 11.1 KB