diff options
| author | Vlastimil Babka <vbabka@suse.cz> | 2025-09-15 15:55:13 +0200 | 
|---|---|---|
| committer | Vlastimil Babka <vbabka@suse.cz> | 2025-09-15 16:48:03 +0200 | 
| commit | 3864e4d5a526870e011e6aadc05645bc93ca3dd6 (patch) | |
| tree | d43e1e299c3e97af2c8d73f1f1c3944d87ab1432 /net/unix/sysctl_net_unix.c | |
| parent | a21fe7b010e32c51c62a86dcba02f9404ed77cac (diff) | |
slab: don't validate slab pointer in free_debug_processing()
The struct slab pointer has been obtained from the object being freed on
all the paths that lead to this function. In all cases this already
includes the test for slab type of the struct page which struct slab is
overlaying. Thus we would not reach this function if it was not a valid
slab pointer in the first place.
One less obvious case is that kmem_cache_free() trusts virt_to_slab()
blindly so it may be NULL if the slab type check is false. But with
SLAB_CONSISTENCY_CHECKS, cache_from_obj() called also from
kmem_cache_free() catches this and returns NULL, which terminates
freeing immediately.
Reviewed-by: Harry Yoo <harry.yoo@oracle.com>
Signed-off-by: Vlastimil Babka <vbabka@suse.cz>
Diffstat (limited to 'net/unix/sysctl_net_unix.c')
0 files changed, 0 insertions, 0 deletions
