mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kronos <kronos@kronoz.cjb.net>
To: linux-kernel@vger.kernel.org
Cc: "Alan Cox" <alan@redhat.com>, kraxel@bytesex.org
Subject: [PATCH] Use after free in drivers/media/video/videodev.c
Date: Sat, 30 Aug 2003 21:55:29 +0200	[thread overview]
Message-ID: <20030830195529.GA15036@dreamland.darkstar.lan> (raw)

Hi,
I think that there's a bug in videdev.c. Look at
video_unregister_device:

void video_unregister_device(struct video_device *vfd) {
        [...]
        class_device_unregister(&vfd->class_dev);
        devfs_remove(vfd->devfs_name);
        video_device[vfd->minor]=NULL;
}

The class_device_unregister will  call video_release. This function will
call  a  ->release callback. As  far  as  I  can  see drivers  do  their
own cleanup  outside video_unregister_device so there is no problem.

However,  if  a  driver  switch to  dynamically  allocated  video_device
this  ->release  callback  will   free  the  struct  video_device  (look
at   video_device_release)   and   possibly  its   container. So   after
class_device_unregister vfd may be a pointer to deallocated memory.

I think that class_device_unregister should be moved down:

--- 2.6.0.orig/drivers/media/video/videodev.c	Tue Aug 12 17:02:29 2003
+++ 2.6.0/drivers/media/video/videodev.c	Sat Aug 30 21:13:29 2003
@@ -349,9 +349,9 @@
 	if(video_device[vfd->minor]!=vfd)
 		panic("videodev: bad unregister");
 
-	class_device_unregister(&vfd->class_dev);
 	devfs_remove(vfd->devfs_name);
 	video_device[vfd->minor]=NULL;
+	class_device_unregister(&vfd->class_dev);
 	up(&videodev_lock);
 }
 

Luca
-- 
Reply-To: kronos@kronoz.cjb.net
Home: http://kronoz.cjb.net
The trouble with computers is that they do what you tell them,
not what you want.
D. Cohen

             reply	other threads:[~2003-08-30 19:55 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-08-30 19:55 Kronos [this message]
2003-08-30 22:21 ` Andrew Morton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20030830195529.GA15036@dreamland.darkstar.lan \
    --to=kronos@kronoz.cjb.net \
    --cc=alan@redhat.com \
    --cc=kraxel@bytesex.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®