mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
rpmsg update for v7.2
Fix use-after-free in rpmsg-char driver. -----BEGIN PGP SIGNATURE----- iQJCBAABCgAsFiEEBd4DzF816k8JZtUlCx85Pw2ZrcUFAmo2pc0OHGJqb3JuQGty eW8uc2UACgkQCx85Pw2ZrcVsQBAArnG1O+UQjt8CViyIknMdrTEplFcYQvSMwyDu jQVcz9Y0exom1+CgZPe9zTuR/wEl7t8O9wxjJm+5w1XeiCXl/CElwaZ5FEZxE5NF xi7jGbvJDVMgxHBTZ4x4hJE+MgxkwKpLn7dKZuXGUi0AkvPsWVusQPrmbPryT8VB 9Qx5FaZMz2wTy92Kx3X9S5/4eixG4zX7cVGAJVlGHxFhxWI3M0S5XxoVClI0aSc7 luhe8bYiA9AtXzEVRI3k2eEeOC/MtSAoZXcU3eef8BhH9YENNv1s4dLHEasN7nuP 9WozrEn2zDrzi38G6RNra+UIxl1lzuNyQaTJGxpKypo71zmJbUgbySmrtwt9akAC ZyXVSKOCp8eZqu1PXFBacsiIDJJEHt2dcgEHXkw0XMl/JSQwEfO5v/ohvnyl9UX4 VpCPjevKae00LUEFA8IhTgfP0zKLqAlFR/aiZrF2s8eJuxv7Y50SWi5ArVj/6ioe B7yDxQNuH/6VM4K29E7vh/81oQETF4x87QNBr1WC26pAMNlPOYrLJ0rvu6fkER+H OXDlA5GpwqrnJJy4fBMISrU3hdqADkttgdW1knRmY9jMP78pwH9eGfpra+p54IzF 28n/ujn+RbksV0cXK/JX7p84Lk9Ik/ZzTkwq2vfSUjZJKI66ASLplZCfqWm+fvyp 6KPym/c= =2sdb -----END PGP SIGNATURE----- Merge tag 'rpmsg-v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux Pull rpmsg update from Bjorn Andersson: - Fix use-after-free in rpmsg-char driver * tag 'rpmsg-v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux: rpmsg: char: Fix use-after-free on probe error path
This commit is contained in:
commit
c7f112e12d
|
|
@ -104,6 +104,9 @@ static int rpmsg_ept_cb(struct rpmsg_device *rpdev, void *buf, int len,
|
|||
struct rpmsg_eptdev *eptdev = priv;
|
||||
struct sk_buff *skb;
|
||||
|
||||
if (!eptdev)
|
||||
return 0;
|
||||
|
||||
skb = alloc_skb(len, GFP_ATOMIC);
|
||||
if (!skb)
|
||||
return -ENOMEM;
|
||||
|
|
@ -124,6 +127,9 @@ static int rpmsg_ept_flow_cb(struct rpmsg_device *rpdev, void *priv, bool enable
|
|||
{
|
||||
struct rpmsg_eptdev *eptdev = priv;
|
||||
|
||||
if (!eptdev)
|
||||
return 0;
|
||||
|
||||
eptdev->remote_flow_restricted = enable;
|
||||
eptdev->remote_flow_updated = true;
|
||||
|
||||
|
|
@ -490,6 +496,7 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev)
|
|||
struct rpmsg_channel_info chinfo;
|
||||
struct rpmsg_eptdev *eptdev;
|
||||
struct device *dev = &rpdev->dev;
|
||||
int ret;
|
||||
|
||||
memcpy(chinfo.name, rpdev->id.name, RPMSG_NAME_SIZE);
|
||||
chinfo.src = rpdev->src;
|
||||
|
|
@ -502,13 +509,17 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev)
|
|||
/* Set the default_ept to the rpmsg device endpoint */
|
||||
eptdev->default_ept = rpdev->ept;
|
||||
|
||||
ret = rpmsg_chrdev_eptdev_add(eptdev, chinfo);
|
||||
|
||||
if (ret)
|
||||
return ret;
|
||||
/*
|
||||
* The rpmsg_ept_cb uses *priv parameter to get its rpmsg_eptdev context.
|
||||
* Storedit in default_ept *priv field.
|
||||
* Stored it in default_ept *priv field.
|
||||
*/
|
||||
eptdev->default_ept->priv = eptdev;
|
||||
|
||||
return rpmsg_chrdev_eptdev_add(eptdev, chinfo);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void rpmsg_chrdev_remove(struct rpmsg_device *rpdev)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user