On 23.04.21 07:40, Juergen Gross wrote: > Commit d3eeb1d77c5d0af ("xen/gntdev: use mmu_interval_notifier_insert") > introduced an error in gntdev_mmap(): in case the call of > mmu_interval_notifier_insert_locked() fails the exit path should not > call mmu_interval_notifier_remove(), as this might result in NULL > dereferences. > > One reason for failure is e.g. a signal pending for the running > process. > > Fixes: d3eeb1d77c5d0af ("xen/gntdev: use mmu_interval_notifier_insert") > Cc: stable@vger.kernel.org > Reported-by: Marek Marczykowski-Górecki > Tested-by: Marek Marczykowski-Górecki > Signed-off-by: Juergen Gross Pushed to xen/tip.git for-linus-5.13b Juergen