Re: [PATCH] ppdev: fix double-free of pp->pdev->name

Jann Horn <[email protected]>
Newsgroups gmane.linux.kernel,gmane.linux.parport
Message-ID <[email protected]>
On Sun, Oct 30, 2016 at 11:24:27PM +0530, Sudip Mukherjee wrote:
> On Sunday 30 October 2016 09:14 PM, Jann Horn wrote:
> >free_pardevice() is called by parport_unregister_device() and already frees
> >pp->pdev->name, don't try to do it again.
> >
> >This bug causes kernel crashes.
> >
> >I found and verified this with KASAN and some added pr_emerg()s:
> >
> >[   60.316568] pp_release: pp->pdev->name == ffff88039cb264c0
> >[   60.316692] free_pardevice: freeing par_dev->name at ffff88039cb264c0
> >[   60.316706] pp_release: kfree(ffff88039cb264c0)
> >[   60.316714] ==========================================================
> >[   60.316722] BUG: Double free or freeing an invalid pointer
> >[   60.316731] Unexpected shadow byte: 0xFB
> >[   60.316801] Object at ffff88039cb264c0, in cache kmalloc-32 size: 32
> >[   60.316813] Allocated:
> >[   60.316824] PID = 1695
> >[   60.316869] Freed:
> >[   60.316880] PID = 1695
> >[   60.316935] ==========================================================
> >
> >CCing Andy Lutomirski because I think this is what broke vmapped stacks
> >for me - after applying this patch, vmapped stacks worked for me.
> >Previously, I got oopses (and lockups) caused by area->pages[0] being
> >0x400000000 in __vunmap(), with area->pages being allocated in the kmalloc
> >area.
> 
> I think the above should not be a part of the commit message.

Ah, yes.

@maintainers: Feel free to remove that from the commit message. Or should I
resend?
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJYFjVEAAoJED4KNFJOeCOoycEQAJ8K982AqNTDt7lHukO+cKr/
XI/uhVsLcQZDGrP18nH38dZqAKOpgrN7E1maaAbOJ+h2TAxwRDH9d0hsrP27Oly6
lRQRHf/unzDUpDhbOP3aB9UsoRWmfwszIALJfmzB96nGsVuuf/7xPDMVqQkql5OC
mGRceOWwyrCMFZqxmhLxhxnSMmS2exRYPEP0/HOyRlSOBjl5YN8bCnsSAdbKHdCj
XKKxqtz8zJ2mS1SLTPPO3wxEekHGhGgG9rgMCu99NEgFPvy8uc2rSjGWVYXMXVpd
uGZBjs2DMx/94wrvQkKTQtvmc6DJICNMdbQ1OjEgxojheLPeXxT/5TXv/RGHD316
+iip8CxPpoiWtOodrj4LN0iMTiSisdX4WZfmJlO6HIg+Z++PKMznamBetl71yj9/
LyqN4h+QB7HahGRCxCTpAAwiCO74GJgN8U1F4sQ0C32OKSjEb1W92O0wovZ4ITJc
2MVV6oRrkJ33MSC4pQhen+O+AtbJBLbWtwNPG0X0yrd0WHl1HIvvoM6VLCerJT/i
qiWbgivRiSDcAbLoxL8B0MyKe5iDm6ssZXVlrM5+7eU9L2evg7RniTDZCYIJRsUR
3+2Pxsgpvb3MtYE5Af7+YtE8+5uakzUP9ZaRqKD+TPPI/hNFAgLRoUxzSe3A6GAN
rTwMEh/I9StVK42SaJRg
=4j9Z
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.