From ba36d54b9aa1eb84f57bb4f2d6f4479efdb98933 Mon Sep 17 00:00:00 2001 From: Pratham Pratap Date: Tue, 23 Mar 2021 00:07:13 +0530 Subject: [PATCH] usb: f_fs: Avoid invalid pointer access in ffs_fs_get_tree Consider a case where ffs_data_new is getting called from ffs_fs_get_tree and ffs_data_new returns error pointer since the function (e.g. adb) is already mounted. The driver is only checking for the NULL return value for ffs but in this case it will not be NULL, which will fail the check and driver will go ahead accessing invalid pointer which can lead to inconsistencies. Fix this by having NULL as well as error pointer check for ffs. Change-Id: Idad5a0b91148325258ea3f545d4da71644c7fc53 Signed-off-by: Pratham Pratap --- drivers/usb/gadget/function/f_fs.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/drivers/usb/gadget/function/f_fs.c b/drivers/usb/gadget/function/f_fs.c index 67f7c2b69222..b6f38174ad18 100644 --- a/drivers/usb/gadget/function/f_fs.c +++ b/drivers/usb/gadget/function/f_fs.c @@ -1760,8 +1760,13 @@ static int ffs_fs_get_tree(struct fs_context *fc) return invalf(fc, "No source specified"); ffs = ffs_data_new(fc->source); - if (unlikely(!ffs)) - return -ENOMEM; + if (IS_ERR_OR_NULL(ffs)) { + if (!ffs) + return -ENOMEM; + else + return PTR_ERR(ffs); + } + ffs->file_perms = ctx->perms; ffs->no_disconnect = ctx->no_disconnect;