mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 05:39:54 -04:00
msm: mhi_dev: Avoiding double free in MHI UCI layer
In mhi_uci_ctrl_set_tiocm(), the control message is submitted to MHI/IPA using mhi_uci_send_packet(). Device waits for completion after this. If the wait is interrupted or is timed out, control message buffer is freed using kfree(). But as the message is already sent, write completion callback is invoked after buffer is freed and same pointer is being freed again. To avoid this double free issue, removing kfree() in mhi_uci_ctrl_set_tiocm(). Once sending of the message is completed, buffer is freed as part of the write completion callback. Change-Id: I6e33ce46fc5506ac45256102221fafb08050a5b5 Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
This commit is contained in:
parent
72c459559a
commit
4dd23ac1ac
1 changed files with 5 additions and 2 deletions
|
|
@ -1748,8 +1748,12 @@ static int mhi_uci_ctrl_set_tiocm(struct uci_client *client,
|
|||
|
||||
reinit_completion(ctrl_client->write_done);
|
||||
ret_val = mhi_uci_send_packet(ctrl_client, ctrl_msg, sizeof(*ctrl_msg));
|
||||
if (ret_val != sizeof(*ctrl_msg))
|
||||
if (ret_val != sizeof(*ctrl_msg)) {
|
||||
uci_log(UCI_DBG_ERROR, "Failed to send ctrl msg\n");
|
||||
kfree(ctrl_msg);
|
||||
ctrl_msg = NULL;
|
||||
goto tiocm_error;
|
||||
}
|
||||
compl_ret = wait_for_completion_interruptible_timeout(
|
||||
ctrl_client->write_done,
|
||||
MHI_UCI_ASYNC_WRITE_TIMEOUT);
|
||||
|
|
@ -1768,7 +1772,6 @@ static int mhi_uci_ctrl_set_tiocm(struct uci_client *client,
|
|||
return 0;
|
||||
|
||||
tiocm_error:
|
||||
kfree(ctrl_msg);
|
||||
return ret_val;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue