From bbbaf52d01f1e40faaac12146aa66b73096a5f26 Mon Sep 17 00:00:00 2001 From: Sriharsha Allenki Date: Tue, 16 Apr 2019 15:33:30 +0530 Subject: [PATCH] usb: dwc3: Prevent use after free of dwc_ipc_log_ctx The dbg_event function call in dwc3_msm_remove after the child dwc3 device is removed is resulting in use after free of dwc_ipc_log_ctx. Even though the dwc_ipc_log_ctx is set to NULL in dwc3_remove, the value is reset once the core platform device is removed because the dwc3 is allocated using devm_kzalloc. This call ensures that the memory is freed up once the device driver is de-registered. Fix this by calling the dbg_event before de-registering the core driver. Change-Id: Ib2cc3d233ea0fd4a1523cae23f57d3cb3753a53f Signed-off-by: Sriharsha Allenki --- drivers/usb/dwc3/dwc3-msm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/dwc3/dwc3-msm.c b/drivers/usb/dwc3/dwc3-msm.c index 893337090574..d6609575cb25 100644 --- a/drivers/usb/dwc3/dwc3-msm.c +++ b/drivers/usb/dwc3/dwc3-msm.c @@ -4589,10 +4589,10 @@ static int dwc3_msm_remove(struct platform_device *pdev) if (mdwc->hs_phy) mdwc->hs_phy->flags &= ~PHY_HOST_MODE; + dbg_event(0xFF, "Remov put", 0); platform_device_put(mdwc->dwc3); of_platform_depopulate(&pdev->dev); - dbg_event(0xFF, "Remov put", 0); pm_runtime_disable(mdwc->dev); pm_runtime_barrier(mdwc->dev); pm_runtime_put_sync(mdwc->dev);