mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-05 19:31:57 -04:00
Merge remote-tracking branch 'sm8350/lineage-20' into lineage-23.2
* sm8350/lineage-20: tipc: fix double-free in tipc_buf_append() FROMGIT: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure UPSTREAM: nfc: llcp: add missing return after LLCP_CLOSED checks Change-Id: Ibf3e62f1100281728cb118786d1d2c4dcaec595a
This commit is contained in:
commit
c8bc4b74db
3 changed files with 18 additions and 2 deletions
|
|
@ -3743,10 +3743,12 @@ static int hidpp_probe(struct hid_device *hdev, const struct hid_device_id *id)
|
|||
|
||||
if (hidpp->quirks & HIDPP_QUIRK_CLASS_G920) {
|
||||
ret = hidpp_ff_init(hidpp, &data);
|
||||
if (ret)
|
||||
if (ret) {
|
||||
hid_warn(hidpp->hid_dev,
|
||||
"Unable to initialize force feedback support, errno %d\n",
|
||||
ret);
|
||||
ret = 0;
|
||||
}
|
||||
}
|
||||
|
||||
return ret;
|
||||
|
|
|
|||
|
|
@ -1096,6 +1096,7 @@ static void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local,
|
|||
if (sk->sk_state == LLCP_CLOSED) {
|
||||
release_sock(sk);
|
||||
nfc_llcp_sock_put(llcp_sock);
|
||||
return;
|
||||
}
|
||||
|
||||
/* Pass the payload upstream */
|
||||
|
|
@ -1187,6 +1188,7 @@ static void nfc_llcp_recv_disc(struct nfc_llcp_local *local,
|
|||
if (sk->sk_state == LLCP_CLOSED) {
|
||||
release_sock(sk);
|
||||
nfc_llcp_sock_put(llcp_sock);
|
||||
return;
|
||||
}
|
||||
|
||||
if (sk->sk_state == LLCP_CONNECTED) {
|
||||
|
|
|
|||
|
|
@ -175,8 +175,20 @@ int tipc_buf_append(struct sk_buff **headbuf, struct sk_buff **buf)
|
|||
|
||||
if (fragid == LAST_FRAGMENT) {
|
||||
TIPC_SKB_CB(head)->validated = false;
|
||||
if (unlikely(!tipc_msg_validate(&head)))
|
||||
|
||||
/* If the reassembled skb has been freed in
|
||||
* tipc_msg_validate() because of an invalid truesize,
|
||||
* then head will point to a newly allocated reassembled
|
||||
* skb, while *headbuf points to freed reassembled skb.
|
||||
* In such cases, correct *headbuf for freeing the newly
|
||||
* allocated reassembled skb later.
|
||||
*/
|
||||
if (unlikely(!tipc_msg_validate(&head))) {
|
||||
if (head != *headbuf)
|
||||
*headbuf = head;
|
||||
goto err;
|
||||
}
|
||||
|
||||
*buf = head;
|
||||
TIPC_SKB_CB(head)->tail = NULL;
|
||||
*headbuf = NULL;
|
||||
|
|
|
|||
Loading…
Reference in a new issue