В ядре Linux устранена следующая уязвимость:
eventfs: инициализировать ei->children и ei->list в init_ei().
eventfs_create_dir() выделяет eventfs_inode и инициализирует его с помощью
init_ei(). Но это не инициализирует eventfs_inode list_heads. Если
eventfs_create_dir() завершается сбоем из-за нехватки памяти, он вызывает
free_ei() перед инициализацией списков и проверяет,
у eventfs_inode нет дочерних элементов.
Но поскольку списка не было
инициализирован, он выдаст ложное предупреждение. Исправьте это, переместив инициализацию списка в init_ei().
[Переписан журнал изменений]
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: eventfs: Initialize ei->children and ei->list in init_ei() eventfs_create_dir() allocates the eventfs_inode and initializes it with init_ei(). But this does not initialize the eventfs_inode list_heads. If the eventfs_create_dir() fails due to memory pressure, it will call free_ei() before it initialized the lists, and that checks to make sure the eventfs_inode has no children. But because the list wasn't initialized, it will give a false warning. Fix it by moving the list initialization into init_ei(). [ Rewrote change log ]