Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1628960 > unrolled thread
| Started by | Pan Bian <bianpan201602@163.com> |
|---|---|
| First post | 2017-04-23 11:40 +0200 |
| Last post | 2017-04-24 22:00 +0200 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 1/1] wan: pc300too: abort path on failure Pan Bian <bianpan201602@163.com> - 2017-04-23 11:40 +0200
Re: [PATCH 1/1] wan: pc300too: abort path on failure David Miller <davem@davemloft.net> - 2017-04-24 22:00 +0200
| From | Pan Bian <bianpan201602@163.com> |
|---|---|
| Date | 2017-04-23 11:40 +0200 |
| Subject | [PATCH 1/1] wan: pc300too: abort path on failure |
| Message-ID | <tzm9R-6K4-21@gated-at.bofh.it> |
From: Pan Bian <bianpan2016@163.com>
In function pc300_pci_init_one(), on the ioremap error path, function
pc300_pci_remove_one() is called to free the allocated memory. However,
the path is not terminated, and the freed memory will be used later,
resulting in use-after-free bugs. This path fixes the bug.
Signed-off-by: Pan Bian <bianpan2016@163.com>
---
drivers/net/wan/pc300too.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wan/pc300too.c b/drivers/net/wan/pc300too.c
index e1dd1ec..b9b934b 100644
--- a/drivers/net/wan/pc300too.c
+++ b/drivers/net/wan/pc300too.c
@@ -346,6 +346,7 @@ static int pc300_pci_init_one(struct pci_dev *pdev,
card->rambase == NULL) {
pr_err("ioremap() failed\n");
pc300_pci_remove_one(pdev);
+ return -ENOMEM;
}
/* PLX PCI 9050 workaround for local configuration register read bug */
--
1.9.1
[toc] | [next] | [standalone]
| From | David Miller <davem@davemloft.net> |
|---|---|
| Date | 2017-04-24 22:00 +0200 |
| Message-ID | <tzSjp-2Lp-45@gated-at.bofh.it> |
| In reply to | #1628960 |
From: Pan Bian <bianpan201602@163.com> Date: Sun, 23 Apr 2017 17:38:35 +0800 > From: Pan Bian <bianpan2016@163.com> > > In function pc300_pci_init_one(), on the ioremap error path, function > pc300_pci_remove_one() is called to free the allocated memory. However, > the path is not terminated, and the freed memory will be used later, > resulting in use-after-free bugs. This path fixes the bug. > > Signed-off-by: Pan Bian <bianpan2016@163.com> Applied.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web