]> git.baikalelectronics.ru Git - kernel.git/commit
PCI/AER: Work around use-after-free in pcie_do_fatal_recovery()
authorThomas Tai <thomas.tai@oracle.com>
Thu, 26 Jul 2018 17:13:04 +0000 (12:13 -0500)
committerBjorn Helgaas <helgaas@kernel.org>
Thu, 26 Jul 2018 17:13:04 +0000 (12:13 -0500)
commitbf2ffc41876bdc5351bd825342654e57b168dd6b
tree3df6c7e55a6802db5af2b11791b52f120ed2ea5f
parenta351502e146b99d7b287162534ea9031abba4a9b
PCI/AER: Work around use-after-free in pcie_do_fatal_recovery()

When an fatal error is received by a non-bridge device, the device is
removed, and pci_stop_and_remove_bus_device() deallocates the device
structure.  The freed device structure is used by subsequent code to send
uevents and print messages.

Hold a reference on the device until we're finished using it.  This is not
an ideal fix because pcie_do_fatal_recovery() should not use the device at
all after removing it, but that's too big a project for right now.

Fixes: bfcbf1909dc0 ("PCI/AER: Handle ERR_FATAL with removal and re-enumeration of devices")
Signed-off-by: Thomas Tai <thomas.tai@oracle.com>
[bhelgaas: changelog, reduce get/put coverage]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
drivers/pci/pcie/err.c