drivers/usb/class/cdc-acm.c: clear dangling pointer
On some failures, the country_code field of an acm structure is freed without freeing the acm structure itself. Elsewhere, operations including memcpy and kfree are performed on the country_code field. The patch sets the country_code field to NULL when it is freed, and likewise sets the country_code_size field to 0. Signed-off-by: Julia Lawall <julia@diku.dk> Acked-by: Oliver Neukum <oneukum@suse.de> Cc: stable <stable@vger.kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
This commit is contained in:
parent
5632c827cb
commit
e7c8e8605d
1 changed files with 4 additions and 0 deletions
|
@ -1230,6 +1230,8 @@ static int acm_probe(struct usb_interface *intf,
|
||||||
i = device_create_file(&intf->dev, &dev_attr_wCountryCodes);
|
i = device_create_file(&intf->dev, &dev_attr_wCountryCodes);
|
||||||
if (i < 0) {
|
if (i < 0) {
|
||||||
kfree(acm->country_codes);
|
kfree(acm->country_codes);
|
||||||
|
acm->country_codes = NULL;
|
||||||
|
acm->country_code_size = 0;
|
||||||
goto skip_countries;
|
goto skip_countries;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -1238,6 +1240,8 @@ static int acm_probe(struct usb_interface *intf,
|
||||||
if (i < 0) {
|
if (i < 0) {
|
||||||
device_remove_file(&intf->dev, &dev_attr_wCountryCodes);
|
device_remove_file(&intf->dev, &dev_attr_wCountryCodes);
|
||||||
kfree(acm->country_codes);
|
kfree(acm->country_codes);
|
||||||
|
acm->country_codes = NULL;
|
||||||
|
acm->country_code_size = 0;
|
||||||
goto skip_countries;
|
goto skip_countries;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in a new issue