mirror of
https://github.com/torvalds/linux.git
synced 2026-10-07 05:31:08 -04:00
iwlwifi: fix freeing uninitialized pointer
If on iwl_dump_nic_event_log() error occurs before that function initialize buf, we process uninitiated pointer in iwl_dbgfs_log_event_read() and can hit "BUG at mm/slub.c:3409" Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=951241 Cc: [email protected] Reported-by: [email protected] Signed-off-by: Stanislaw Gruszka <[email protected]> Reviewed-by: Emmanuel Grumbach <[email protected]> Signed-off-by: Johannes Berg <[email protected]>
This commit is contained in:
1 parent
0aed849f61
commit
3309ccf7fc
1 file changed
+8
-8
@@ -2237,15 +2237,15 @@ static ssize_t iwl_dbgfs_log_event_read(struct file *file,
|
||||
size_t count, loff_t *ppos)
|
||||
{
|
||||
struct iwl_priv *priv = file->private_data;
|
||||
char *buf;
|
||||
int pos = 0;
|
||||
ssize_t ret = -ENOMEM;
|
||||
char *buf = NULL;
|
||||
ssize_t ret;
|
||||
|
||||
ret = pos = iwl_dump_nic_event_log(priv, true, &buf, true);
|
||||
if (buf) {
|
||||
ret = simple_read_from_buffer(user_buf, count, ppos, buf, pos);
|
||||
kfree(buf);
|
||||
}
|
||||
ret = iwl_dump_nic_event_log(priv, true, &buf, true);
|
||||
if (ret < 0)
|
||||
goto err;
|
||||
ret = simple_read_from_buffer(user_buf, count, ppos, buf, ret);
|
||||
err:
|
||||
kfree(buf);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user