Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1370911

Re: [PATCH] mtd: gpmi: fix raw_buffer pointer double free issue

From Richard Weinberger <richard@nod.at>
Newsgroups linux.kernel
Subject Re: [PATCH] mtd: gpmi: fix raw_buffer pointer double free issue
Date 2016-04-04 23:40 +0200
Message-ID <rkko2-VB-5@gated-at.bofh.it> (permalink)
References <rkjLk-pb-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Am 04.04.2016 um 22:41 schrieb Han Xu:
> fix the raw_buffer pointer double free issue found by coverify.
> 
> CID 18344 (#2 of 2): Double free (USE_AFTER_FREE)
> 3. double_free: Calling gpmi_alloc_dma_buffer frees pointer
> this->raw_buffer which has already been freed
> 
> Signed-off-by: Han Xu <han.xu@nxp.com>
> ---
> 
> changes in v2:
>  - add coverity check log
> ---
>  drivers/mtd/nand/gpmi-nand/gpmi-nand.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/drivers/mtd/nand/gpmi-nand/gpmi-nand.c b/drivers/mtd/nand/gpmi-nand/gpmi-nand.c
> index 8122c69..dcb60b0 100644
> --- a/drivers/mtd/nand/gpmi-nand/gpmi-nand.c
> +++ b/drivers/mtd/nand/gpmi-nand/gpmi-nand.c
> @@ -797,6 +797,7 @@ static void gpmi_free_dma_buffer(struct gpmi_nand_data *this)
>  
>  	this->cmd_buffer	= NULL;
>  	this->data_buffer_dma	= NULL;
> +	this->raw_buffer	= NULL;
>  	this->page_buffer_virt	= NULL;
>  	this->page_buffer_size	=  0;

Reviewed-by: Richard Weinberger <richard@nod.at>

Aside of that, the driver should IMHO be fixed to not call
gpmi_free_dma_buffer() multiple times on the same buffer...

Thanks,
//richard

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH] mtd: gpmi: fix raw_buffer pointer double free issue Han Xu <han.xu@nxp.com> - 2016-04-04 23:00 +0200
  Re: [PATCH] mtd: gpmi: fix raw_buffer pointer double free issue Richard Weinberger <richard@nod.at> - 2016-04-04 23:40 +0200
  Re: [PATCH] mtd: gpmi: fix raw_buffer pointer double free issue Boris Brezillon <boris.brezillon@free-electrons.com> - 2016-04-05 17:50 +0200

csiph-web