It may lead a null-ptr-deref in hfs_find_init() by mounting a crafted hfs filesystem. So We need check tree in hfs_find_init(). Signed-off-by: Yang Yingliang <yangyingliang@xxxxxxxxxx> --- fs/hfsplus/bfind.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/fs/hfsplus/bfind.c b/fs/hfsplus/bfind.c index ca2ba8c..85bef3e 100644 --- a/fs/hfsplus/bfind.c +++ b/fs/hfsplus/bfind.c @@ -16,6 +16,9 @@ int hfs_find_init(struct hfs_btree *tree, struct hfs_find_data *fd) { void *ptr; + if (!tree) + return -EINVAL; + fd->tree = tree; fd->bnode = NULL; ptr = kmalloc(tree->max_key_len * 2 + 4, GFP_KERNEL); -- 1.8.3