From: Hans de Goede <hdegoede@redhat.com>
To: Aleksandr Burakov <a.burakov@rosalinux.ru>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
stable@vger.kernel.org, Mark Gross <markgross@kernel.org>
Cc: linux-kernel@vger.kernel.org, lvc-project@linuxtesting.org,
lvc-patches@linuxtesting.org,
platform-driver-x86@vger.kernel.org
Subject: Re: [PATCH 6.1] platform/x86: android-platform: deref after free in x86_android_tablet_init() fix
Date: Tue, 17 Sep 2024 15:03:56 +0200 [thread overview]
Message-ID: <ae37b670-a42d-4130-911c-90e0c8b828bc@redhat.com> (raw)
In-Reply-To: <20240917120458.7300-1-a.burakov@rosalinux.ru>
Hi,
Thank you for your patch.
On 9/17/24 2:04 PM, Aleksandr Burakov wrote:
> No upstream commit exists for this commit.
Right, which is bad, especially since the upstream code actually still has this bug.
NACK.
Note that upstream in drivers/platform/x86/x86-android-tablets/core.c
the same issue is also present around line 447:
pdevs[pdev_count] = platform_device_register_data(&pdev->dev, "gpio-keys",
PLATFORM_DEVID_AUTO,
&pdata, sizeof(pdata));
if (IS_ERR(pdevs[pdev_count])) {
x86_android_tablet_remove(pdev);
return PTR_ERR(pdevs[pdev_count]);
}
pdev_count++;
Please submit a fix for both issues upstream, once that has been merged
you can submit a backport with a proper upstream commit reference.
Regards,
Hans
>
> Pointer '&pdevs[i]' is dereferenced at x86_android_tablet_init()
> after the referenced memory was deallocated by calling function
> 'x86_android_tablet_cleanup()'.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: 5eba0141206e ("platform/x86: x86-android-tablets: Add support for instantiating platform-devs")
> Signed-off-by: Aleksandr Burakov <a.burakov@rosalinux.ru>
> ---
> drivers/platform/x86/x86-android-tablets.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/platform/x86/x86-android-tablets.c b/drivers/platform/x86/x86-android-tablets.c
> index 9178076d9d7d..9838c5332201 100644
> --- a/drivers/platform/x86/x86-android-tablets.c
> +++ b/drivers/platform/x86/x86-android-tablets.c
> @@ -1853,8 +1853,9 @@ static __init int x86_android_tablet_init(void)
> for (i = 0; i < pdev_count; i++) {
> pdevs[i] = platform_device_register_full(&dev_info->pdev_info[i]);
> if (IS_ERR(pdevs[i])) {
> + int ret = PTR_ERR(pdevs[i]);
> x86_android_tablet_cleanup();
> - return PTR_ERR(pdevs[i]);
> + return ret;
> }
> }
>
next prev parent reply other threads:[~2024-09-17 13:04 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-17 12:04 Aleksandr Burakov
2024-09-17 13:03 ` Hans de Goede [this message]
2024-09-17 18:55 ` [lvc-patches] " Sergey Shtylyov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ae37b670-a42d-4130-911c-90e0c8b828bc@redhat.com \
--to=hdegoede@redhat.com \
--cc=a.burakov@rosalinux.ru \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lvc-patches@linuxtesting.org \
--cc=lvc-project@linuxtesting.org \
--cc=markgross@kernel.org \
--cc=platform-driver-x86@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®