Merge remote-tracking branch 'sm8350/lineage-20' into lineage-23.2

* sm8350/lineage-20:
  tipc: fix double-free in tipc_buf_append()
  FROMGIT: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
  UPSTREAM: nfc: llcp: add missing return after LLCP_CLOSED checks

Change-Id: Ibf3e62f1100281728cb118786d1d2c4dcaec595a
This commit is contained in:
Michael Bestas 2026-09-09 01:16:28 +03:00
commit c8bc4b74db
No known key found for this signature in database
3 changed files with 18 additions and 2 deletions

View file

@ -3743,10 +3743,12 @@ static int hidpp_probe(struct hid_device *hdev, const struct hid_device_id *id)
if (hidpp->quirks & HIDPP_QUIRK_CLASS_G920) {
ret = hidpp_ff_init(hidpp, &data);
if (ret)
if (ret) {
hid_warn(hidpp->hid_dev,
"Unable to initialize force feedback support, errno %d\n",
ret);
ret = 0;
}
}
return ret;

View file

@ -1096,6 +1096,7 @@ static void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local,
if (sk->sk_state == LLCP_CLOSED) {
release_sock(sk);
nfc_llcp_sock_put(llcp_sock);
return;
}
/* Pass the payload upstream */
@ -1187,6 +1188,7 @@ static void nfc_llcp_recv_disc(struct nfc_llcp_local *local,
if (sk->sk_state == LLCP_CLOSED) {
release_sock(sk);
nfc_llcp_sock_put(llcp_sock);
return;
}
if (sk->sk_state == LLCP_CONNECTED) {

View file

@ -175,8 +175,20 @@ int tipc_buf_append(struct sk_buff **headbuf, struct sk_buff **buf)
if (fragid == LAST_FRAGMENT) {
TIPC_SKB_CB(head)->validated = false;
if (unlikely(!tipc_msg_validate(&head)))
/* If the reassembled skb has been freed in
* tipc_msg_validate() because of an invalid truesize,
* then head will point to a newly allocated reassembled
* skb, while *headbuf points to freed reassembled skb.
* In such cases, correct *headbuf for freeing the newly
* allocated reassembled skb later.
*/
if (unlikely(!tipc_msg_validate(&head))) {
if (head != *headbuf)
*headbuf = head;
goto err;
}
*buf = head;
TIPC_SKB_CB(head)->tail = NULL;
*headbuf = NULL;