Skip to content

Commit

Permalink
net: fddi: fix UAF in fza_probe
Browse files Browse the repository at this point in the history
commit deb7178 upstream.

fp is netdev private data and it cannot be
used after free_netdev() call. Using fp after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() after error message.

Fixes: 61414f5 ("FDDI: defza: Add support for DEC FDDIcontroller 700
TURBOchannel adapter")
Signed-off-by: Pavel Skripkin <paskripkin@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
  • Loading branch information
pskrgag authored and gregkh committed Jul 25, 2021
1 parent 66c73f1 commit f336059
Showing 1 changed file with 1 addition and 2 deletions.
3 changes: 1 addition & 2 deletions drivers/net/fddi/defza.c
Expand Up @@ -1504,9 +1504,8 @@ static int fza_probe(struct device *bdev)
release_mem_region(start, len);

err_out_kfree:
free_netdev(dev);

pr_err("%s: initialization failure, aborting!\n", fp->name);
free_netdev(dev);
return ret;
}

Expand Down

0 comments on commit f336059

Please sign in to comment.