Commit aa340845 authored by Dan Carpenter's avatar Dan Carpenter Committed by Jens Axboe

io_uring: fix a use after free in io_async_task_func()

The "apoll" variable is freed and then used on the next line.  We need
to move the free down a few lines.

Fixes: 0be0b0e3 ("io_uring: simplify io_async_task_func()")
Signed-off-by: default avatarDan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: default avatarJens Axboe <axboe@kernel.dk>
parent b2edc0a7
...@@ -4655,12 +4655,13 @@ static void io_async_task_func(struct callback_head *cb) ...@@ -4655,12 +4655,13 @@ static void io_async_task_func(struct callback_head *cb)
/* restore ->work in case we need to retry again */ /* restore ->work in case we need to retry again */
if (req->flags & REQ_F_WORK_INITIALIZED) if (req->flags & REQ_F_WORK_INITIALIZED)
memcpy(&req->work, &apoll->work, sizeof(req->work)); memcpy(&req->work, &apoll->work, sizeof(req->work));
kfree(apoll);
if (!READ_ONCE(apoll->poll.canceled)) if (!READ_ONCE(apoll->poll.canceled))
__io_req_task_submit(req); __io_req_task_submit(req);
else else
__io_req_task_cancel(req, -ECANCELED); __io_req_task_cancel(req, -ECANCELED);
kfree(apoll);
} }
static int io_async_wake(struct wait_queue_entry *wait, unsigned mode, int sync, static int io_async_wake(struct wait_queue_entry *wait, unsigned mode, int sync,
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment