mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
s390/ism: folio_put() after error
dmb->cpu_addr was allocated via folio_alloc(). Use folio_put() instead of
kfree() in the error exit of ism_alloc_dmb() to avoid slab allocator
corruption.
While at it, reset dmb->cpu_addr after folio_put to avoid unintentional UAF
by future callers.
Fixes: 83781384a9 ("s390/ism: Properly fix receive message buffer allocation")
Signed-off-by: Alexandra Winter <wintera@linux.ibm.com>
Reviewed-by: Gerd Bayer <gbayer@linux.ibm.com>
Link: https://patch.msgid.link/20260902143733.433574-1-wintera@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
1668a31e3b
commit
907a56ab3e
|
|
@ -231,6 +231,7 @@ static void ism_free_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
|
|||
dma_unmap_page(&ism->pdev->dev, dmb->dma_addr, dmb->dmb_len,
|
||||
DMA_FROM_DEVICE);
|
||||
folio_put(virt_to_folio(dmb->cpu_addr));
|
||||
dmb->cpu_addr = NULL;
|
||||
}
|
||||
|
||||
static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
|
||||
|
|
@ -274,7 +275,8 @@ static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
|
|||
return 0;
|
||||
|
||||
out_free:
|
||||
kfree(dmb->cpu_addr);
|
||||
folio_put(folio);
|
||||
dmb->cpu_addr = NULL;
|
||||
out_bit:
|
||||
clear_bit(dmb->idx, ism->sba_bitmap);
|
||||
return rc;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user