Commit 70632249 authored by Eric Sesterhenn's avatar Eric Sesterhenn Committed by Linus Torvalds
Fix hfsplus oops on image without extents

Fix an oops with a corrupted hfs+ image.


 for details.

Problem is that we call hfs_btree_open() from hfsplus_fill_super() to set
HFSPLUS_SB(sb).[ext_tree|cat_tree] Both trees are still NULL at this moment.
If hfs_btree_open() fails for any reason it calls iput() on the page, which
gets to hfsplus_releasepage() which tries to access HFSPLUS_SB(sb).* which is
still NULL and oopses while dereferencing it.

[ build fix]
Signed-off-by: default avatarEric Sesterhenn <>
Cc: Roman Zippel <>
Signed-off-by: default avatarAndrew Morton <>
Signed-off-by: default avatarLinus Torvalds <>
parent 4413a0f6
......@@ -65,6 +65,8 @@ static int hfsplus_releasepage(struct page *page, gfp_t mask)
return 0;
if (!tree)
return 0;
if (tree->node_size >= PAGE_CACHE_SIZE) {
nidx = page->index >> (tree->node_size_shift - PAGE_CACHE_SHIFT);
