From 3b8fe1bc8e6263d83bad4756d1fe0da0490c2d3e Mon Sep 17 00:00:00 2001 From: Bojun Pan Date: Wed, 9 Sep 2020 15:06:26 -0700 Subject: [PATCH] msm: ipa: fix the use-after-free on qmi framework in ssr scenario IPA drvier free the qmi server hdl without notify the qmi framework which is causing the use-after-free on QMI framework. The fix is to notify qmi framework before freeing the qmi handle. Change-Id: I1ec9d3efd29283fddd958561a538b2995222a53c Signed-off-by: Bojun Pan --- drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c b/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c index 9d1eac1a6d9b..f379a4fbe0ba 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c @@ -1507,6 +1507,7 @@ static void ipa3_q6_clnt_svc_arrive(struct work_struct *work) IPAWANERR( "ipa3_qmi_init_modem_send_sync_msg failed due to SSR!\n"); /* Cleanup when ipa3_wwan_remove is called */ + qmi_handle_release(ipa_q6_clnt); vfree(ipa_q6_clnt); ipa_q6_clnt = NULL; return;