Linux: Fix use-after-free in zfsvfs_create()
Coverity reported that we pass a pointer to zfsvfs to `dmu_objset_disown()` after freeing zfsvfs in zfsvfs_create_impl() after a failure in zfsvfs_init(). We have nearly identical duplicate versions of this code for FreeBSD and Linux, but interestingly, the FreeBSD version of this code differs in such a way that it does not suffer from this bug. We remove the difference from the FreeBSD version to fix this bug. Reviewed-by:Brian Behlendorf <behlendorf1@llnl.gov> Signed-off-by:
Richard Yao <richard.yao@alumni.stonybrook.edu> Closes #13883
Showing
+2 -3
Please register or sign in to comment