+31
−23
Loading
Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more
The logics in pipe_advance() used to release all buffers past the new position failed in cases when the number of buffers to release was equal to pipe->buffers. If that happened, none of them had been released, leaving pipe full. Worse, it was trivial to trigger and we end up with pipe full of uninitialized pages. IOW, it's an infoleak. Cc: stable@vger.kernel.org # v4.9 Reported-by:"Alan J. Wylie" <alan@wylie.me.uk> Tested-by:
"Alan J. Wylie" <alan@wylie.me.uk> Signed-off-by:
Al Viro <viro@zeniv.linux.org.uk>