]> git.baikalelectronics.ru Git - kernel.git/commit
staging: vme_user: Fix possible UAF in tsi148_dma_list_add
authorGaosheng Cui <cuigaosheng1@huawei.com>
Thu, 17 Nov 2022 03:59:14 +0000 (11:59 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 31 Dec 2022 12:32:39 +0000 (13:32 +0100)
commit8676f0fdb89c7db9b6ed4a867f7804d17f5e4ca3
tree8b1991f3b2b761c37fccbc4d4a40e06abba18f1d
parent1e0c20034e8fecef87bafc70530c75f5b9eb2fc7
staging: vme_user: Fix possible UAF in tsi148_dma_list_add

[ Upstream commit e777327669d4bc836aa2ab067da7300e0cc47e7b ]

Smatch report warning as follows:

drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn:
  '&entry->list' not removed from list

In tsi148_dma_list_add(), the error path "goto err_dma" will not
remove entry->list from list->entries, but entry will be freed,
then list traversal may cause UAF.

Fix by removeing it from list->entries before free().

Fixes: f744fc62d579 ("vme: tsi148: fix first DMA item mapping")
Signed-off-by: Gaosheng Cui <cuigaosheng1@huawei.com>
Link: https://lore.kernel.org/r/20221117035914.2954454-1-cuigaosheng1@huawei.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/staging/vme_user/vme_tsi148.c