* [PATCH] USB: serial: Fix use after free in debug printk
@ 2024-10-31 6:59 Dan Carpenter
2024-10-31 9:07 ` Johan Hovold
0 siblings, 1 reply; 5+ messages in thread
From: Dan Carpenter @ 2024-10-31 6:59 UTC (permalink / raw)
To: Greg Kroah-Hartman; +Cc: Johan Hovold, linux-usb, linux-kernel, kernel-janitors
The dev_dbg() call dereferences "urb" but it was already freed on the
previous line. Move the debug output earlier in the function.
Fixes: 984f68683298 ("USB: serial: io_edgeport.c: remove dbg() usage")
Cc: stable@vger.kernel.org
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
---
drivers/usb/serial/io_edgeport.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/drivers/usb/serial/io_edgeport.c b/drivers/usb/serial/io_edgeport.c
index c7d6b5e3f898..b8f1bd41fb24 100644
--- a/drivers/usb/serial/io_edgeport.c
+++ b/drivers/usb/serial/io_edgeport.c
@@ -775,7 +775,10 @@ static void edge_bulk_out_cmd_callback(struct urb *urb)
atomic_dec(&CmdUrbs);
dev_dbg(&urb->dev->dev, "%s - FREE URB %p (outstanding %d)\n",
__func__, urb, atomic_read(&CmdUrbs));
-
+ if (status)
+ dev_dbg(&urb->dev->dev,
+ "%s - nonzero write bulk status received: %d\n",
+ __func__, status);
/* clean up the transfer buffer */
kfree(urb->transfer_buffer);
@@ -783,12 +786,8 @@ static void edge_bulk_out_cmd_callback(struct urb *urb)
/* Free the command urb */
usb_free_urb(urb);
- if (status) {
- dev_dbg(&urb->dev->dev,
- "%s - nonzero write bulk status received: %d\n",
- __func__, status);
+ if (status)
return;
- }
/* tell the tty driver that something has changed */
if (edge_port->open)
--
2.45.2
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] USB: serial: Fix use after free in debug printk
2024-10-31 6:59 [PATCH] USB: serial: Fix use after free in debug printk Dan Carpenter
@ 2024-10-31 9:07 ` Johan Hovold
2024-10-31 9:35 ` Dan Carpenter
0 siblings, 1 reply; 5+ messages in thread
From: Johan Hovold @ 2024-10-31 9:07 UTC (permalink / raw)
To: Dan Carpenter
Cc: Greg Kroah-Hartman, linux-usb, linux-kernel, kernel-janitors
On Thu, Oct 31, 2024 at 09:59:10AM +0300, Dan Carpenter wrote:
> The dev_dbg() call dereferences "urb" but it was already freed on the
> previous line. Move the debug output earlier in the function.
Thanks for catching this, but please use a temporary variable for the
struct device pointer instead of changing the flow.
Also make sure to include the driver name in the patch summary prefix
(i.e. "USB: serial: io_edgeport: ..."):
> Fixes: 984f68683298 ("USB: serial: io_edgeport.c: remove dbg() usage")
> Cc: stable@vger.kernel.org
> Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Johan
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] USB: serial: Fix use after free in debug printk
2024-10-31 9:07 ` Johan Hovold
@ 2024-10-31 9:35 ` Dan Carpenter
2024-10-31 9:39 ` Dan Carpenter
0 siblings, 1 reply; 5+ messages in thread
From: Dan Carpenter @ 2024-10-31 9:35 UTC (permalink / raw)
To: Johan Hovold; +Cc: Greg Kroah-Hartman, linux-usb, linux-kernel, kernel-janitors
On Thu, Oct 31, 2024 at 10:07:42AM +0100, Johan Hovold wrote:
> On Thu, Oct 31, 2024 at 09:59:10AM +0300, Dan Carpenter wrote:
> > The dev_dbg() call dereferences "urb" but it was already freed on the
> > previous line. Move the debug output earlier in the function.
>
> Thanks for catching this, but please use a temporary variable for the
> struct device pointer instead of changing the flow.
>
Why? The output is the same either way and this way is cleaner code.
> Also make sure to include the driver name in the patch summary prefix
> (i.e. "USB: serial: io_edgeport: ..."):
Sure.
regards,
dan carpenter
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] USB: serial: Fix use after free in debug printk
2024-10-31 9:35 ` Dan Carpenter
@ 2024-10-31 9:39 ` Dan Carpenter
2024-10-31 13:21 ` Johan Hovold
0 siblings, 1 reply; 5+ messages in thread
From: Dan Carpenter @ 2024-10-31 9:39 UTC (permalink / raw)
To: Johan Hovold; +Cc: Greg Kroah-Hartman, linux-usb, linux-kernel, kernel-janitors
On Thu, Oct 31, 2024 at 12:35:31PM +0300, Dan Carpenter wrote:
> On Thu, Oct 31, 2024 at 10:07:42AM +0100, Johan Hovold wrote:
> > On Thu, Oct 31, 2024 at 09:59:10AM +0300, Dan Carpenter wrote:
> > > The dev_dbg() call dereferences "urb" but it was already freed on the
> > > previous line. Move the debug output earlier in the function.
> >
> > Thanks for catching this, but please use a temporary variable for the
> > struct device pointer instead of changing the flow.
> >
>
> Why? The output is the same either way and this way is cleaner code.
>
Nah, you're right. A temporary variable is nicer. It avoids having two if
statements.
regards,
dan carpenter
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] USB: serial: Fix use after free in debug printk
2024-10-31 9:39 ` Dan Carpenter
@ 2024-10-31 13:21 ` Johan Hovold
0 siblings, 0 replies; 5+ messages in thread
From: Johan Hovold @ 2024-10-31 13:21 UTC (permalink / raw)
To: Dan Carpenter
Cc: Greg Kroah-Hartman, linux-usb, linux-kernel, kernel-janitors
On Thu, Oct 31, 2024 at 12:39:10PM +0300, Dan Carpenter wrote:
> On Thu, Oct 31, 2024 at 12:35:31PM +0300, Dan Carpenter wrote:
> > On Thu, Oct 31, 2024 at 10:07:42AM +0100, Johan Hovold wrote:
> > > On Thu, Oct 31, 2024 at 09:59:10AM +0300, Dan Carpenter wrote:
> > > > The dev_dbg() call dereferences "urb" but it was already freed on the
> > > > previous line. Move the debug output earlier in the function.
> > >
> > > Thanks for catching this, but please use a temporary variable for the
> > > struct device pointer instead of changing the flow.
> >
> > Why? The output is the same either way and this way is cleaner code.
>
> Nah, you're right. A temporary variable is nicer. It avoids having two if
> statements.
Yeah, and the debug printk belongs with the return.
v2 now applied, thanks.
Johan
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2024-10-31 13:21 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-10-31 6:59 [PATCH] USB: serial: Fix use after free in debug printk Dan Carpenter
2024-10-31 9:07 ` Johan Hovold
2024-10-31 9:35 ` Dan Carpenter
2024-10-31 9:39 ` Dan Carpenter
2024-10-31 13:21 ` Johan Hovold
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®