Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1499891
| From | Tahsin Erdogan <tahsin@google.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [BUG] errors in void transport_add_device() function |
| Date | 2016-10-12 21:00 +0200 |
| Message-ID | <srwUW-8js-9@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
transport_add_device() is declared as void but it can actually fail.
Since the caller has no knowledge of the error, a later call to
transport_remove_device() may cause a kernel crash.
An example is a memory allocation error in this call path:
int device_private_init(struct device *dev)
{
dev->p = kzalloc(sizeof(*dev->p), GFP_KERNEL);
device_private_init
device_add
attribute_container_add_class_device
transport_add_class_device
attribute_container_device_trigger
transport_add_device
This results in a NULL pointer access in device_del():
if (parent)
klist_del(&dev->p->knode_parent);
klist_del
device_del
attribute_container_class_device_del
transport_remove_classdev
attribute_container_device_trigger
transport_remove_device
Back to linux.kernel | Previous | Next | Find similar | Unroll thread
[BUG] errors in void transport_add_device() function Tahsin Erdogan <tahsin@google.com> - 2016-10-12 21:00 +0200
csiph-web