From: Qinglang Miao Date: Fri, 20 Nov 2020 07:48:47 +0000 (+0800) Subject: mips: cdmm: fix use-after-free in mips_cdmm_bus_discover X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=f0e82242b16826077a2775eacfe201d803bb7a22;p=linux.git mips: cdmm: fix use-after-free in mips_cdmm_bus_discover kfree(dev) has been called inside put_device so anther kfree would cause a use-after-free bug/ Fixes: 8286ae03308c ("MIPS: Add CDMM bus support") Reported-by: Hulk Robot Signed-off-by: Qinglang Miao Acked-by: Serge Semin Signed-off-by: Thomas Bogendoerfer --- diff --git a/drivers/bus/mips_cdmm.c b/drivers/bus/mips_cdmm.c index 9f7ed1fcd4285..626dedd110cbc 100644 --- a/drivers/bus/mips_cdmm.c +++ b/drivers/bus/mips_cdmm.c @@ -559,10 +559,8 @@ static void mips_cdmm_bus_discover(struct mips_cdmm_bus *bus) dev_set_name(&dev->dev, "cdmm%u-%u", cpu, id); ++id; ret = device_register(&dev->dev); - if (ret) { + if (ret) put_device(&dev->dev); - kfree(dev); - } } }