Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1628960 > unrolled thread

[PATCH 1/1] wan: pc300too: abort path on failure

Started byPan Bian <bianpan201602@163.com>
First post2017-04-23 11:40 +0200
Last post2017-04-24 22:00 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 1/1] wan: pc300too: abort path on failure Pan Bian <bianpan201602@163.com> - 2017-04-23 11:40 +0200
    Re: [PATCH 1/1] wan: pc300too: abort path on failure David Miller <davem@davemloft.net> - 2017-04-24 22:00 +0200

#1628960 — [PATCH 1/1] wan: pc300too: abort path on failure

FromPan Bian <bianpan201602@163.com>
Date2017-04-23 11:40 +0200
Subject[PATCH 1/1] wan: pc300too: abort path on failure
Message-ID<tzm9R-6K4-21@gated-at.bofh.it>
From: Pan Bian <bianpan2016@163.com>

In function pc300_pci_init_one(), on the ioremap error path, function
pc300_pci_remove_one() is called to free the allocated memory. However,
the path is not terminated, and the freed memory will be used later,
resulting in use-after-free bugs. This path fixes the bug.

Signed-off-by: Pan Bian <bianpan2016@163.com>
---
 drivers/net/wan/pc300too.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/wan/pc300too.c b/drivers/net/wan/pc300too.c
index e1dd1ec..b9b934b 100644
--- a/drivers/net/wan/pc300too.c
+++ b/drivers/net/wan/pc300too.c
@@ -346,6 +346,7 @@ static int pc300_pci_init_one(struct pci_dev *pdev,
 	    card->rambase == NULL) {
 		pr_err("ioremap() failed\n");
 		pc300_pci_remove_one(pdev);
+		return -ENOMEM;
 	}
 
 	/* PLX PCI 9050 workaround for local configuration register read bug */
-- 
1.9.1

[toc] | [next] | [standalone]


#1629935

FromDavid Miller <davem@davemloft.net>
Date2017-04-24 22:00 +0200
Message-ID<tzSjp-2Lp-45@gated-at.bofh.it>
In reply to#1628960
From: Pan Bian <bianpan201602@163.com>
Date: Sun, 23 Apr 2017 17:38:35 +0800

> From: Pan Bian <bianpan2016@163.com>
> 
> In function pc300_pci_init_one(), on the ioremap error path, function
> pc300_pci_remove_one() is called to free the allocated memory. However,
> the path is not terminated, and the freed memory will be used later,
> resulting in use-after-free bugs. This path fixes the bug.
> 
> Signed-off-by: Pan Bian <bianpan2016@163.com>

Applied.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web