s390/ism: folio_put() after error

dmb->cpu_addr was allocated via folio_alloc(). Use folio_put() instead of
kfree() in the error exit of ism_alloc_dmb() to avoid slab allocator
corruption.

While at it, reset dmb->cpu_addr after folio_put to avoid unintentional UAF
by future callers.

Fixes: 83781384a9 ("s390/ism: Properly fix receive message buffer allocation")
Signed-off-by: Alexandra Winter <wintera@linux.ibm.com>
Reviewed-by: Gerd Bayer <gbayer@linux.ibm.com>
Link: https://patch.msgid.link/20260902143733.433574-1-wintera@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
Alexandra Winter 2026-09-02 16:37:33 +02:00 committed by Jakub Kicinski
parent 1668a31e3b
commit 907a56ab3e

View File

@ -231,6 +231,7 @@ static void ism_free_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
dma_unmap_page(&ism->pdev->dev, dmb->dma_addr, dmb->dmb_len,
DMA_FROM_DEVICE);
folio_put(virt_to_folio(dmb->cpu_addr));
dmb->cpu_addr = NULL;
}
static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
@ -274,7 +275,8 @@ static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
return 0;
out_free:
kfree(dmb->cpu_addr);
folio_put(folio);
dmb->cpu_addr = NULL;
out_bit:
clear_bit(dmb->idx, ism->sba_bitmap);
return rc;