[patch]double frees in error code paths of ipaq driver
Oliver Neukum <[email protected]>
| Newsgroups | gmane.linux.usb.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, the error code paths can be enter with buffers to freed buffers. Serial core would do a kfree() on memory already freed. Regards Oliver Signed-off-by: Oliver Neukum <[email protected]> --- --- a/drivers/usb/serial/ipaq.c 2007-09-17 20:05:26.000000000 +0200 +++ b/drivers/usb/serial/ipaq.c 2007-09-17 20:07:06.000000000 +0200 @@ -646,11 +646,13 @@ static int ipaq_open(struct usb_serial_p kfree(port->bulk_out_buffer); port->bulk_in_buffer = kmalloc(URBDATA_SIZE, GFP_KERNEL); if (port->bulk_in_buffer == NULL) { + port->bulk_out_buffer = NULL; /* prevent double free */ goto enomem; } port->bulk_out_buffer = kmalloc(URBDATA_SIZE, GFP_KERNEL); if (port->bulk_out_buffer == NULL) { kfree(port->bulk_in_buffer); + port->bulk_in_buffer = NULL; goto enomem; } port->read_urb->transfer_buffer = port->bulk_in_buffer; ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ [email protected] To unsubscribe, use the last form field at: https://lists.sourceforge.net/lists/listinfo/linux-usb-devel