* [PATCH] Sound, 6Fire USB: Fix double-free bug in usb6fire_fw_ezusb_upload()
@ 2011-06-13 21:52 Jesper Juhl
2011-06-14 5:28 ` Takashi Iwai
0 siblings, 1 reply; 2+ messages in thread
From: Jesper Juhl @ 2011-06-13 21:52 UTC (permalink / raw)
To: linux-kernel
Cc: alsa-devel, Daniel Mack, Lucas De Marchi, Torsten Schenk,
Takashi Iwai, Jaroslav Kysela
We have a double-free bug in
sound/usb/6fire/firmware.c::usb6fire_fw_ezusb_upload().
We already call release_firmware(fw) on line 258, so when we then do it
again after usb6fire_fw_ezusb_write() returns <0, we have a double-free.
Easily fixed by just removing the last call to release_firmware().
Signed-off-by: Jesper Juhl <jj@chaosbits.net>
---
firmware.c | 1 -
1 file changed, 1 deletion(-)
Patch against Linus' tree (head at 40779859de0f73b40390c6401a024d06cf024290).
diff --git a/sound/usb/6fire/firmware.c b/sound/usb/6fire/firmware.c
index a91719d..1e3ae33 100644
--- a/sound/usb/6fire/firmware.c
+++ b/sound/usb/6fire/firmware.c
@@ -270,7 +270,6 @@ static int usb6fire_fw_ezusb_upload(
data = 0x00; /* resume ezusb cpu */
ret = usb6fire_fw_ezusb_write(device, 0xa0, 0xe600, &data, 1);
if (ret < 0) {
- release_firmware(fw);
snd_printk(KERN_ERR PREFIX "unable to upload ezusb "
"firmware %s: end message.\n", fwname);
return ret;
--
Jesper Juhl <jj@chaosbits.net> http://www.chaosbits.net/
Don't top-post http://www.catb.org/jargon/html/T/top-post.html
Plain text mails only, please.
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] Sound, 6Fire USB: Fix double-free bug in usb6fire_fw_ezusb_upload()
2011-06-13 21:52 [PATCH] Sound, 6Fire USB: Fix double-free bug in usb6fire_fw_ezusb_upload() Jesper Juhl
@ 2011-06-14 5:28 ` Takashi Iwai
0 siblings, 0 replies; 2+ messages in thread
From: Takashi Iwai @ 2011-06-14 5:28 UTC (permalink / raw)
To: Jesper Juhl
Cc: linux-kernel, alsa-devel, Daniel Mack, Lucas De Marchi,
Torsten Schenk, Jaroslav Kysela
At Mon, 13 Jun 2011 23:52:02 +0200 (CEST),
Jesper Juhl wrote:
>
> We have a double-free bug in
> sound/usb/6fire/firmware.c::usb6fire_fw_ezusb_upload().
> We already call release_firmware(fw) on line 258, so when we then do it
> again after usb6fire_fw_ezusb_write() returns <0, we have a double-free.
> Easily fixed by just removing the last call to release_firmware().
>
> Signed-off-by: Jesper Juhl <jj@chaosbits.net>
Applied now. Thanks.
Takashi
> ---
> firmware.c | 1 -
> 1 file changed, 1 deletion(-)
>
> Patch against Linus' tree (head at 40779859de0f73b40390c6401a024d06cf024290).
>
> diff --git a/sound/usb/6fire/firmware.c b/sound/usb/6fire/firmware.c
> index a91719d..1e3ae33 100644
> --- a/sound/usb/6fire/firmware.c
> +++ b/sound/usb/6fire/firmware.c
> @@ -270,7 +270,6 @@ static int usb6fire_fw_ezusb_upload(
> data = 0x00; /* resume ezusb cpu */
> ret = usb6fire_fw_ezusb_write(device, 0xa0, 0xe600, &data, 1);
> if (ret < 0) {
> - release_firmware(fw);
> snd_printk(KERN_ERR PREFIX "unable to upload ezusb "
> "firmware %s: end message.\n", fwname);
> return ret;
>
>
> --
> Jesper Juhl <jj@chaosbits.net> http://www.chaosbits.net/
> Don't top-post http://www.catb.org/jargon/html/T/top-post.html
> Plain text mails only, please.
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2011-06-14 5:28 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2011-06-13 21:52 [PATCH] Sound, 6Fire USB: Fix double-free bug in usb6fire_fw_ezusb_upload() Jesper Juhl
2011-06-14 5:28 ` Takashi Iwai
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®