Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1499891

[BUG] errors in void transport_add_device() function

From Tahsin Erdogan <tahsin@google.com>
Newsgroups linux.kernel
Subject [BUG] errors in void transport_add_device() function
Date 2016-10-12 21:00 +0200
Message-ID <srwUW-8js-9@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


transport_add_device() is declared as void but it can actually fail.
Since the caller has no knowledge of the error, a later call to
transport_remove_device() may cause a kernel crash.

An example is a memory allocation error in this call path:

int device_private_init(struct device *dev)
{
        dev->p = kzalloc(sizeof(*dev->p), GFP_KERNEL);

device_private_init
device_add
attribute_container_add_class_device
transport_add_class_device
attribute_container_device_trigger
transport_add_device


This results in a NULL pointer access in device_del():

        if (parent)
                klist_del(&dev->p->knode_parent);

klist_del
device_del
attribute_container_class_device_del
transport_remove_classdev
attribute_container_device_trigger
transport_remove_device

Back to linux.kernel | Previous | Next | Find similar | Unroll thread


Thread

[BUG] errors in void transport_add_device() function Tahsin Erdogan <tahsin@google.com> - 2016-10-12 21:00 +0200

csiph-web