[PATCH AUTOSEL for 4.14 08/64] apparmor: fix leak of null profile name if profile allocation fails

From: alexander . levin
Date: Sat Dec 02 2017 - 11:26:12 EST


From: John Johansen <john.johansen@xxxxxxxxxxxxx>

[ Upstream commit 4633307e5ed6128975595df43f796a10c41d11c1 ]

Fixes: d07881d2edb0 ("apparmor: move new_null_profile to after profile lookup fns()")
Reported-by: Seth Arnold <seth.arnold@xxxxxxxxxxxxx>
Signed-off-by: John Johansen <john.johansen@xxxxxxxxxxxxx>
Signed-off-by: Sasha Levin <alexander.levin@xxxxxxxxxxx>
---
security/apparmor/policy.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/security/apparmor/policy.c b/security/apparmor/policy.c
index 4243b0c3f0e4..586b249d3b46 100644
--- a/security/apparmor/policy.c
+++ b/security/apparmor/policy.c
@@ -502,7 +502,7 @@ struct aa_profile *aa_new_null_profile(struct aa_profile *parent, bool hat,
{
struct aa_profile *p, *profile;
const char *bname;
- char *name;
+ char *name = NULL;

AA_BUG(!parent);

@@ -562,6 +562,7 @@ out:
return profile;

fail:
+ kfree(name);
aa_free_profile(profile);
return NULL;
}
--
2.11.0