nvdimm: Fix dereference after free in register_nvdimm_pmu()
authorKonstantin Meskhidze <konstantin.meskhidze@huawei.com>
Thu, 17 Aug 2023 11:41:03 +0000 (19:41 +0800)
committerDave Jiang <dave.jiang@intel.com>
Thu, 17 Aug 2023 16:34:03 +0000 (09:34 -0700)
'nd_pmu->pmu.attr_groups' is dereferenced in function
'nvdimm_pmu_free_hotplug_memory' call after it has been freed. Because in
function 'nvdimm_pmu_free_hotplug_memory' memory pointed by the fields of
'nd_pmu->pmu.attr_groups' is deallocated it is necessary to call 'kfree'
after 'nvdimm_pmu_free_hotplug_memory'.

Fixes: 0fab1ba6ad6b ("drivers/nvdimm: Add perf interface to expose nvdimm performance stats")
Co-developed-by: Ivanov Mikhail <ivanov.mikhail1@huawei-partners.com>
Signed-off-by: Konstantin Meskhidze <konstantin.meskhidze@huawei.com>
Reviewed-by: Jeff Moyer <jmoyer@redhat.com>
Link: https://lore.kernel.org/r/20230817114103.754977-1-konstantin.meskhidze@huawei.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
drivers/nvdimm/nd_perf.c

index 14881c4e03e6bb01bdd55cf0cbdd20339e202bbf..2b6dc80d8fb5b04e85d8426760b3e5fdaf98680c 100644 (file)
@@ -308,8 +308,8 @@ int register_nvdimm_pmu(struct nvdimm_pmu *nd_pmu, struct platform_device *pdev)
 
        rc = perf_pmu_register(&nd_pmu->pmu, nd_pmu->pmu.name, -1);
        if (rc) {
-               kfree(nd_pmu->pmu.attr_groups);
                nvdimm_pmu_free_hotplug_memory(nd_pmu);
+               kfree(nd_pmu->pmu.attr_groups);
                return rc;
        }