mirror of
https://github.com/torvalds/linux.git
synced 2026-10-11 21:07:03 +02:00
bnx2x: fix double free in bnx2x_init_firmware() error path
bnx2x_init_firmware() frees bp->init_ops, bp->init_data and
bp->init_ops_offsets in its error path without setting them to NULL.
The cleanup function bnx2x_release_firmware() frees the same three
pointers unconditionally, so if init_firmware fails and
release_firmware is later called (e.g. from __bnx2x_remove or through
the function state machine), all three are freed a second time.
Set each pointer to NULL after kfree() in the error path so that the
subsequent kfree(NULL) in bnx2x_release_firmware() is a safe no-op.
Fixes: 94a78b79cb ("bnx2x: Separated FW from the source.")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260815122149.951215-1-yijiangshan@kylinos.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
d2c26c2911
commit
d2796ffe38
|
|
@ -13473,10 +13473,13 @@ static int bnx2x_init_firmware(struct bnx2x *bp)
|
|||
|
||||
iro_alloc_err:
|
||||
kfree(bp->init_ops_offsets);
|
||||
bp->init_ops_offsets = NULL;
|
||||
init_offsets_alloc_err:
|
||||
kfree(bp->init_ops);
|
||||
bp->init_ops = NULL;
|
||||
init_ops_alloc_err:
|
||||
kfree(bp->init_data);
|
||||
bp->init_data = NULL;
|
||||
request_firmware_exit:
|
||||
release_firmware(bp->firmware);
|
||||
bp->firmware = NULL;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user