On Wed, Feb 17, 2016 at 11:38:05AM -0500, Joe Korty wrote:
> Fix kfree bug in recvmsg and sendmsg.
> 
> We cannot kfree(iov) when iov points to an array on the
> stack, as that has the potential of corrupting memory.
> 
> So re-introduce the if-stmt that used to protect kfree
> from this condition, code that was removed as part of
> a larger set of changes made by git commit da184284.

NAK.  You are misreading import_iovec():
        *iov = p == *iov ? NULL : p;
in the end will have iov replaced with NULL if we ended up using what
it originally pointed to.

Reply via email to