Skip to content

Commit 3c7c806

Browse files
Dan Carpentergregkh
authored andcommitted
sh: intc: Fix use-after-free bug in register_intc_controller()
[ Upstream commit 63e72e551942642c48456a4134975136cdcb9b3c ] In the error handling for this function, d is freed without ever removing it from intc_list which would lead to a use after free. To fix this, let's only add it to the list after everything has succeeded. Fixes: 2dcec7a ("sh: intc: set_irq_wake() support") Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org> Reviewed-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de> Signed-off-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de> Signed-off-by: Sasha Levin <sashal@kernel.org>
1 parent 94a6159 commit 3c7c806

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

drivers/sh/intc/core.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -194,7 +194,6 @@ int __init register_intc_controller(struct intc_desc *desc)
194194
goto err0;
195195

196196
INIT_LIST_HEAD(&d->list);
197-
list_add_tail(&d->list, &intc_list);
198197

199198
raw_spin_lock_init(&d->lock);
200199
INIT_RADIX_TREE(&d->tree, GFP_ATOMIC);
@@ -380,6 +379,7 @@ int __init register_intc_controller(struct intc_desc *desc)
380379

381380
d->skip_suspend = desc->skip_syscore_suspend;
382381

382+
list_add_tail(&d->list, &intc_list);
383383
nr_intc_controllers++;
384384

385385
return 0;

0 commit comments

Comments
 (0)