mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 12:44:03 +02:00
mtd: mtdswap: Avoid freeing registered blktrans device twice
In mtdswap_add_mtd(), debugfs setup failure after successful blktrans
registration can free mbd_dev twice.
add_mtd_blktrans_dev() initializes the blktrans device reference and
publishes the disk. Once that succeeds, del_mtd_blktrans_dev() tears the
disk down and drops the blktrans reference; when that reference reaches
zero, blktrans_dev_release() frees the mtd_blktrans_dev.
The debugfs failure path called del_mtd_blktrans_dev(mbd_dev), then fell
through the common cleanup label and called kfree(mbd_dev) again. Clear
the local pointer after deregistration so the common cleanup can still
release the mtdswap state without freeing the blktrans object twice.
This issue was found by a static analysis checker and confirmed by
manual source review.
Fixes: e8e3edb95c ("mtd: create per-device and module-scope debugfs entries")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
This commit is contained in:
parent
e9290031f7
commit
779aa4c66a
|
|
@ -1450,6 +1450,7 @@ static void mtdswap_add_mtd(struct mtd_blktrans_ops *tr, struct mtd_info *mtd)
|
|||
|
||||
debugfs_failed:
|
||||
del_mtd_blktrans_dev(mbd_dev);
|
||||
mbd_dev = NULL;
|
||||
|
||||
cleanup:
|
||||
mtdswap_cleanup(d);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user