[PATCH] drivers/base/node: fix UAF on device_register() failure

Linkai Gong <[email protected]>
Newsgroups dev.linux.lists.driver-core,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
node_init_node_access() frees the access node with kfree() if
device_register() fails. After device_register() the embedded device is
initialized and must be released with put_device() so that
node_access_release() can free it.

Use the same put_device error path style as node_init_cache_dev().

Fixes: 08d9dbe72b1f ("node: Link memory nodes to their compute nodes")
Signed-off-by: Linkai Gong <[email protected]>
---
 drivers/base/node.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/base/node.c b/drivers/base/node.c
index 3da91929ad4e..d2fd57c2edc8 100644
--- a/drivers/base/node.c
+++ b/drivers/base/node.c
@@ -176,8 +176,10 @@ static struct node_access_nodes *node_init_node_access(struct node *node,
 	pm_runtime_no_callbacks(dev);
 	list_add_tail(&access_node->list_node, &node->access_list);
 	return access_node;
+
 free_name:
-	kfree_const(dev->kobj.name);
+	put_device(dev);
+	return NULL;
 free:
 	kfree(access_node);
 	return NULL;
-- 
2.25.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.