Explorar o código

power_supply: Fix use after free and memory leak

device_unregister() might free its argument.  This leads to freed
memory use in kfree().  Also use put_device() instead of kfree()
as dev may be already used in another layer after call to device_add().

Signed-off-by: Vasiliy Kulikov <segoon@openwall.com>
Signed-off-by: Anton Vorontsov <cbouatmailru@gmail.com>
Vasiliy Kulikov %!s(int64=15) %!d(string=hai) anos
pai
achega
3a2dbd611b
Modificáronse 1 ficheiros con 2 adicións e 2 borrados
  1. 2 2
      drivers/power/power_supply_core.c

+ 2 - 2
drivers/power/power_supply_core.c

@@ -190,10 +190,10 @@ int power_supply_register(struct device *parent, struct power_supply *psy)
 	goto success;
 
 create_triggers_failed:
-	device_unregister(psy->dev);
+	device_del(dev);
 kobject_set_name_failed:
 device_add_failed:
-	kfree(dev);
+	put_device(dev);
 success:
 	return rc;
 }