mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 13:49:24 -04:00
haven: dbl: Fix use-after-free in tx/rx unregister
The hh_dbl_tx_unregister() and hh_dbl_rx_unregister() functions tries to dereference client_desc in pr_debug(), which would have already been freed if the tx/rx's counterpart was unregistered. Hence, move the pr_debug() statements right before the section where kfree() is called on client_desc to avoid use-after-free. Change-Id: I183b0a3df0665ab90a85e0907b39641cd19f4923 Signed-off-by: Raghavendra Rao Ananta <rananta@codeaurora.org>
This commit is contained in:
parent
e5734f3793
commit
beb519f70a
1 changed files with 6 additions and 6 deletions
|
|
@ -443,6 +443,9 @@ int hh_dbl_tx_unregister(void *dbl_client_desc)
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
pr_debug("%s: Unregistering client for label: %d\n",
|
||||
__func__, client_desc->label);
|
||||
|
||||
/* Rx client still holding the "client_desc". Do not remove now. */
|
||||
if (!cap_table_entry->rx_reg_done) {
|
||||
cap_table_entry->client_desc = NULL;
|
||||
|
|
@ -454,9 +457,6 @@ int hh_dbl_tx_unregister(void *dbl_client_desc)
|
|||
cap_table_entry->tx_reg_done = 0;
|
||||
mutex_unlock(&cap_table_entry->cap_entry_lock);
|
||||
|
||||
pr_debug("%s: Unregistered client for label: %d\n",
|
||||
__func__, client_desc->label);
|
||||
|
||||
return 0;
|
||||
}
|
||||
EXPORT_SYMBOL(hh_dbl_tx_unregister);
|
||||
|
|
@ -494,6 +494,9 @@ int hh_dbl_rx_unregister(void *dbl_client_desc)
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
pr_debug("%s: Unregistering client for label: %d\n", __func__,
|
||||
client_desc->label);
|
||||
|
||||
/* Tx client still holding the "client_desc". Do not remove now.*/
|
||||
if (!cap_table_entry->tx_reg_done) {
|
||||
cap_table_entry->client_desc = NULL;
|
||||
|
|
@ -508,9 +511,6 @@ int hh_dbl_rx_unregister(void *dbl_client_desc)
|
|||
|
||||
mutex_unlock(&cap_table_entry->cap_entry_lock);
|
||||
|
||||
pr_debug("%s: Unregistered client for label: %d\n", __func__,
|
||||
client_desc->label);
|
||||
|
||||
return 0;
|
||||
}
|
||||
EXPORT_SYMBOL(hh_dbl_rx_unregister);
|
||||
|
|
|
|||
Loading…
Reference in a new issue