autofs-5.1.4 - fix fd leak in rpc_do_create_client() From: Ian Kent Commit 94f87e203a (fix create_client() RPC client handling) fixed possible use of an invalid RPC client handle but the change neglected to account for a check in rpc_do_create_client() that would open a new file descriptor without checking if the passed in descriptor was already opened. Signed-off-by: Ian Kent --- CHANGELOG | 1 + lib/rpc_subs.c | 4 ++-- 2 files changed, 3 insertions(+), 2 deletions(-) --- autofs-5.1.4.orig/CHANGELOG +++ autofs-5.1.4/CHANGELOG @@ -67,6 +67,7 @@ - fix prefix option handling in expand_entry(). - fix sublink option not set from defaults. - fix error return in do_nfs_mount(). +- fix fd leak in rpc_do_create_client(). 24/05/2017 autofs-5.1.3 ======================= --- autofs-5.1.4.orig/lib/rpc_subs.c +++ autofs-5.1.4/lib/rpc_subs.c @@ -183,7 +183,7 @@ static int rpc_do_create_client(struct s in4_laddr.sin_addr.s_addr = htonl(INADDR_ANY); slen = sizeof(struct sockaddr_in); - if (!info->client) { + if (!info->client && *fd == RPC_ANYSOCK) { struct sockaddr *laddr; *fd = open_sock(addr->sa_family, type, proto); @@ -296,7 +296,7 @@ static int rpc_do_create_client(struct s * it would bind to a reserved port, which has been shown to * exhaust the reserved port range in some situations. */ - if (!info->client) { + if (!info->client && *fd == RPC_ANYSOCK) { *fd = open_sock(addr->sa_family, type, proto); if (*fd < 0) { ret = -errno;