mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] firmware_class: avoid double free
@ 2004-10-02 16:51 Duncan Sands
  0 siblings, 0 replies; only message in thread
From: Duncan Sands @ 2004-10-02 16:51 UTC (permalink / raw)
  To: linux-kernel

The error exit path in request_firmware frees the allocated
struct firmware *firmware, which is good.  What is not so good
is that the value of firmware has already been copied out to the
caller as *firmware_p.  The risk is that the caller will pass this
to release_firmware, a double free.  This is exactly what will
happen if the caller copied the example code

         if(request_firmware(&fw_entry, $FIRMWARE, device) == 0)
                copy_fw_to_device(fw_entry->data, fw_entry->size);
         release(fw_entry);

from the firmware documentation.

--- mm/drivers/base/firmware_class.c.orig	2004-10-02 18:43:00.323005656 +0200
+++ mm/drivers/base/firmware_class.c	2004-10-02 18:43:37.500448654 +0200
@@ -441,6 +441,7 @@
 
 error_kfree_fw:
 	kfree(firmware);
+	*firmware_p = NULL;
 out:
 	return retval;
 }

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2004-10-02 16:51 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-10-02 16:51 [PATCH] firmware_class: avoid double free Duncan Sands

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®