mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
hwmon: (corsair-cpro) Remove debugfs entries when probe fails
ccp_debugfs_init() registers debugfs files whose private data is the devm
allocated ccp. If hwmon_device_register_with_info() fails right after it,
ccp_probe() returns without removing them: the HID core then frees ccp,
and ccp_remove() is not called for a failed probe, so the files stay
behind. Reading one of them dereferences the freed pointer.
Remove the debugfs entries on that error path. debugfs_remove_recursive()
waits for readers already inside the show callbacks, so ccp is no longer
reachable through debugfs by the time probe returns.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-hwmon/20260708031612.BD7E61F000E9@smtp.kernel.org/
Fixes: 5997eb60f8 ("hwmon: (corsair-cpro) Add firmware and bootloader information")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Link: https://patch.msgid.link/20260828061949.3151191-1-lilinmao@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
This commit is contained in:
parent
09a9e1746a
commit
4ee875c423
|
|
@ -642,13 +642,15 @@ static int ccp_probe(struct hid_device *hdev, const struct hid_device_id *id)
|
|||
ccp, &ccp_chip_info, NULL);
|
||||
if (IS_ERR(ccp->hwmon_dev)) {
|
||||
ret = PTR_ERR(ccp->hwmon_dev);
|
||||
goto out_hw_close;
|
||||
goto out_debugfs_remove;
|
||||
}
|
||||
|
||||
ccp_debugfs_init(ccp, fw_valid, bl_valid);
|
||||
|
||||
return 0;
|
||||
|
||||
out_debugfs_remove:
|
||||
debugfs_remove_recursive(ccp->debugfs);
|
||||
out_hw_close:
|
||||
hid_hw_close(hdev);
|
||||
hid_device_io_stop(hdev);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user