Commit 7ae2c3c2 authored by Alan Stern's avatar Alan Stern Committed by Greg Kroah-Hartman

USB: UDC core: fix double-free in usb_add_gadget_udc_release

The error-handling pathways in usb_add_gadget_udc_release() are messed
up.  Aside from the uninformative statement labels, they can deallocate
the udc structure after calling put_device(), which is a double-free.
This was observed by KASAN in automatic testing.

This patch cleans up the routine.  It preserves the requirement that
when any failure occurs, we call put_device(&gadget->dev).
Signed-off-by: default avatarAlan Stern <stern@rowland.harvard.edu>
Reported-by: default avatarFengguang Wu <fengguang.wu@intel.com>
CC: <stable@vger.kernel.org>
Reviewed-by: default avatarPeter Chen <peter.chen@nxp.com>
Acked-by: default avatarFelipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent 46eb14a6
...@@ -1147,11 +1147,7 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget, ...@@ -1147,11 +1147,7 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget,
udc = kzalloc(sizeof(*udc), GFP_KERNEL); udc = kzalloc(sizeof(*udc), GFP_KERNEL);
if (!udc) if (!udc)
goto err1; goto err_put_gadget;
ret = device_add(&gadget->dev);
if (ret)
goto err2;
device_initialize(&udc->dev); device_initialize(&udc->dev);
udc->dev.release = usb_udc_release; udc->dev.release = usb_udc_release;
...@@ -1160,7 +1156,11 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget, ...@@ -1160,7 +1156,11 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget,
udc->dev.parent = parent; udc->dev.parent = parent;
ret = dev_set_name(&udc->dev, "%s", kobject_name(&parent->kobj)); ret = dev_set_name(&udc->dev, "%s", kobject_name(&parent->kobj));
if (ret) if (ret)
goto err3; goto err_put_udc;
ret = device_add(&gadget->dev);
if (ret)
goto err_put_udc;
udc->gadget = gadget; udc->gadget = gadget;
gadget->udc = udc; gadget->udc = udc;
...@@ -1170,7 +1170,7 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget, ...@@ -1170,7 +1170,7 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget,
ret = device_add(&udc->dev); ret = device_add(&udc->dev);
if (ret) if (ret)
goto err4; goto err_unlist_udc;
usb_gadget_set_state(gadget, USB_STATE_NOTATTACHED); usb_gadget_set_state(gadget, USB_STATE_NOTATTACHED);
udc->vbus = true; udc->vbus = true;
...@@ -1178,27 +1178,25 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget, ...@@ -1178,27 +1178,25 @@ int usb_add_gadget_udc_release(struct device *parent, struct usb_gadget *gadget,
/* pick up one of pending gadget drivers */ /* pick up one of pending gadget drivers */
ret = check_pending_gadget_drivers(udc); ret = check_pending_gadget_drivers(udc);
if (ret) if (ret)
goto err5; goto err_del_udc;
mutex_unlock(&udc_lock); mutex_unlock(&udc_lock);
return 0; return 0;
err5: err_del_udc:
device_del(&udc->dev); device_del(&udc->dev);
err4: err_unlist_udc:
list_del(&udc->list); list_del(&udc->list);
mutex_unlock(&udc_lock); mutex_unlock(&udc_lock);
err3:
put_device(&udc->dev);
device_del(&gadget->dev); device_del(&gadget->dev);
err2: err_put_udc:
kfree(udc); put_device(&udc->dev);
err1: err_put_gadget:
put_device(&gadget->dev); put_device(&gadget->dev);
return ret; return ret;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment