mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 10:09:10 +02:00
i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
If devm_platform_get_and_ioremap_resource() returns an error,
mlxbf_i2c_init_resource() frees tmp_res before reading tmp_res->io to
get the error code. This results in a use-after-free.
Save the error code before freeing tmp_res.
Fixes: b5b5b32081 ("i2c: mlxbf: I2C SMBus driver for Mellanox BlueField SoC")
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Cc: <stable@vger.kernel.org> # v5.10+
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260714150808.85045-1-xuanqiang.luo@linux.dev
This commit is contained in:
parent
9db20d23aa
commit
71356737a7
|
|
@ -1051,8 +1051,10 @@ static int mlxbf_i2c_init_resource(struct platform_device *pdev,
|
|||
|
||||
tmp_res->io = devm_platform_get_and_ioremap_resource(pdev, type, &tmp_res->params);
|
||||
if (IS_ERR(tmp_res->io)) {
|
||||
int ret = PTR_ERR(tmp_res->io);
|
||||
|
||||
devm_kfree(dev, tmp_res);
|
||||
return PTR_ERR(tmp_res->io);
|
||||
return ret;
|
||||
}
|
||||
|
||||
tmp_res->type = type;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user