Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 5c22837a authored by Oliver Neukum's avatar Oliver Neukum Committed by Greg Kroah-Hartman
Browse files

USB: cdc-wdm: fix race leading leading to memory corruption



This patch fixes a race whereby a pointer to a buffer
would be overwritten while the buffer was in use leading
to a double free and a memory leak. This causes crashes.
This bug was introduced in 2.6.34

Signed-off-by: default avatarOliver Neukum <oneukum@suse.de>
Tested-by: default avatarBjørn Mork <bjorn@mork.no>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent 151b6128
Loading
Loading
Loading
Loading
+5 −2
Original line number Original line Diff line number Diff line
@@ -157,8 +157,9 @@ static void wdm_out_callback(struct urb *urb)
	spin_lock(&desc->iuspin);
	spin_lock(&desc->iuspin);
	desc->werr = urb->status;
	desc->werr = urb->status;
	spin_unlock(&desc->iuspin);
	spin_unlock(&desc->iuspin);
	clear_bit(WDM_IN_USE, &desc->flags);
	kfree(desc->outbuf);
	kfree(desc->outbuf);
	desc->outbuf = NULL;
	clear_bit(WDM_IN_USE, &desc->flags);
	wake_up(&desc->wait);
	wake_up(&desc->wait);
}
}


@@ -338,7 +339,7 @@ static ssize_t wdm_write
	if (we < 0)
	if (we < 0)
		return -EIO;
		return -EIO;


	desc->outbuf = buf = kmalloc(count, GFP_KERNEL);
	buf = kmalloc(count, GFP_KERNEL);
	if (!buf) {
	if (!buf) {
		rv = -ENOMEM;
		rv = -ENOMEM;
		goto outnl;
		goto outnl;
@@ -406,10 +407,12 @@ static ssize_t wdm_write
	req->wIndex = desc->inum;
	req->wIndex = desc->inum;
	req->wLength = cpu_to_le16(count);
	req->wLength = cpu_to_le16(count);
	set_bit(WDM_IN_USE, &desc->flags);
	set_bit(WDM_IN_USE, &desc->flags);
	desc->outbuf = buf;


	rv = usb_submit_urb(desc->command, GFP_KERNEL);
	rv = usb_submit_urb(desc->command, GFP_KERNEL);
	if (rv < 0) {
	if (rv < 0) {
		kfree(buf);
		kfree(buf);
		desc->outbuf = NULL;
		clear_bit(WDM_IN_USE, &desc->flags);
		clear_bit(WDM_IN_USE, &desc->flags);
		dev_err(&desc->intf->dev, "Tx URB error: %d\n", rv);
		dev_err(&desc->intf->dev, "Tx URB error: %d\n", rv);
	} else {
	} else {