From patchwork Sun Nov 30 12:51:03 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ard Biesheuvel X-Patchwork-Id: 41717 Return-Path: X-Original-To: linaro@patches.linaro.org Delivered-To: linaro@patches.linaro.org Received: from mail-wi0-f200.google.com (mail-wi0-f200.google.com [209.85.212.200]) by ip-10-151-82-157.ec2.internal (Postfix) with ESMTPS id 8DC1B24001 for ; Sun, 30 Nov 2014 12:53:30 +0000 (UTC) Received: by mail-wi0-f200.google.com with SMTP id ex7sf5732517wid.11 for ; Sun, 30 Nov 2014 04:53:29 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:delivered-to:from:to:subject:date:message-id:cc :precedence:list-id:list-unsubscribe:list-archive:list-post :list-help:list-subscribe:mime-version:content-type :content-transfer-encoding:sender:errors-to:x-original-sender :x-original-authentication-results:mailing-list; bh=4jdqjcCiJUwqe1nTdzOfWBy1eBpzvaoe2HF3yciW8Fg=; b=CVTv/YIXieSQjwhrPapn2T/61I+Yvw4FgJProhOmZh0ZbJOes5AeG0omRWreIBYj3g Yvb32H8ut21acGIiC3As/FgWO3tH12laIHysRN49CqghJtVgKqJe3aiMtYzwTwNfQZAz fl/GDrM0j+YG7viYcO/jKiAaIgPkVMiD0cX5di3f9MBkjKOwLSkba6aO8ArV2Bx2RSHH CCmpWQRVn9lRRoax72VSF/fxB8AWZgJMlmkVq8RptACYSnJuHmqcnZNh4sKIHEPXON6y s2P5jGKgNM5nJF4aWMpcPe5f/HjHMoJ7huF7M/b2UsgfHEltVhBRrGGMUHUqd8CBrLVO zLrQ== X-Gm-Message-State: ALoCoQm25EMHW4CjaXbYpDjs5ojqtymAt76et/c8kNhpbkzCK16kzuY6JVFspHuTGQjh0QPPYctb X-Received: by 10.181.13.147 with SMTP id ey19mr12371151wid.2.1417352009800; Sun, 30 Nov 2014 04:53:29 -0800 (PST) X-BeenThere: patchwork-forward@linaro.org Received: by 10.152.5.74 with SMTP id q10ls108498laq.43.gmail; Sun, 30 Nov 2014 04:53:29 -0800 (PST) X-Received: by 10.152.5.167 with SMTP id t7mr30331917lat.9.1417352009442; Sun, 30 Nov 2014 04:53:29 -0800 (PST) Received: from mail-lb0-f169.google.com (mail-lb0-f169.google.com. [209.85.217.169]) by mx.google.com with ESMTPS id j9si12234796lam.35.2014.11.30.04.53.29 for (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sun, 30 Nov 2014 04:53:29 -0800 (PST) Received-SPF: pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.217.169 as permitted sender) client-ip=209.85.217.169; Received: by mail-lb0-f169.google.com with SMTP id p9so7432250lbv.28 for ; Sun, 30 Nov 2014 04:53:29 -0800 (PST) X-Received: by 10.152.2.165 with SMTP id 5mr4505218lav.40.1417352009336; Sun, 30 Nov 2014 04:53:29 -0800 (PST) X-Forwarded-To: patchwork-forward@linaro.org X-Forwarded-For: patch@linaro.org patchwork-forward@linaro.org Delivered-To: patch@linaro.org Received: by 10.112.184.201 with SMTP id ew9csp138550lbc; Sun, 30 Nov 2014 04:53:28 -0800 (PST) X-Received: by 10.70.102.77 with SMTP id fm13mr37961742pdb.96.1417352007790; Sun, 30 Nov 2014 04:53:27 -0800 (PST) Received: from bombadil.infradead.org (bombadil.infradead.org. [2001:1868:205::9]) by mx.google.com with ESMTPS id s5si24382131pdg.142.2014.11.30.04.53.27 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 30 Nov 2014 04:53:27 -0800 (PST) Received-SPF: none (google.com: linux-mtd-bounces+patch=linaro.org@lists.infradead.org does not designate permitted sender hosts) client-ip=2001:1868:205::9; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.80.1 #2 (Red Hat Linux)) id 1Xv3yO-0003zd-PT; Sun, 30 Nov 2014 12:51:32 +0000 Received: from mail-wi0-f172.google.com ([209.85.212.172]) by bombadil.infradead.org with esmtps (Exim 4.80.1 #2 (Red Hat Linux)) id 1Xv3yN-0003rM-D9 for linux-mtd@lists.infradead.org; Sun, 30 Nov 2014 12:51:31 +0000 Received: by mail-wi0-f172.google.com with SMTP id n3so22060117wiv.17 for ; Sun, 30 Nov 2014 04:51:07 -0800 (PST) X-Received: by 10.194.238.3 with SMTP id vg3mr47211632wjc.69.1417351866959; Sun, 30 Nov 2014 04:51:06 -0800 (PST) Received: from ards-macbook-pro.local (cag06-7-83-153-85-71.fbx.proxad.net. [83.153.85.71]) by mx.google.com with ESMTPSA id bj7sm23164170wjc.33.2014.11.30.04.51.05 for (version=TLSv1.1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sun, 30 Nov 2014 04:51:06 -0800 (PST) From: Ard Biesheuvel To: dwmw2@infradead.org, computersforpeace@gmail.com, linux-mtd@lists.infradead.org Subject: [PATCH] mtd: physmap_of: fix potential NULL dereference Date: Sun, 30 Nov 2014 13:51:03 +0100 Message-Id: <1417351863-3812-1-git-send-email-ard.biesheuvel@linaro.org> X-Mailer: git-send-email 1.8.3.2 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20141130_045131_596664_91DAA435 X-CRM114-Status: GOOD ( 13.01 ) X-Spam-Score: -0.7 (/) X-Spam-Report: SpamAssassin version 3.4.0 on bombadil.infradead.org summary: Content analysis details: (-0.7 points) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.212.172 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [209.85.212.172 listed in wl.mailspike.net] -0.0 RCVD_IN_MSPIKE_WL Mailspike good senders Cc: Ard Biesheuvel X-BeenThere: linux-mtd@lists.infradead.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: , List-Help: , List-Subscribe: , MIME-Version: 1.0 Sender: "linux-mtd" Errors-To: linux-mtd-bounces+patch=linaro.org@lists.infradead.org X-Removed-Original-Auth: Dkim didn't pass. X-Original-Sender: ard.biesheuvel@linaro.org X-Original-Authentication-Results: mx.google.com; spf=pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.217.169 as permitted sender) smtp.mail=patch+caf_=patchwork-forward=linaro.org@linaro.org Mailing-list: list patchwork-forward@linaro.org; contact patchwork-forward+owners@linaro.org X-Google-Group-Id: 836684582541 On device remove, when testing the cmtd field of an of_flash struct to decide whether it is a concatenated device or not, we get a false positive on cmtd == NULL, and dereference it subsequently. This may occur if of_flash_remove() is called from the cleanup path of of_flash_probe(). Instead, test for NULL first, and only then perform the test for a concatenated device. Signed-off-by: Ard Biesheuvel --- drivers/mtd/maps/physmap_of.c | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/drivers/mtd/maps/physmap_of.c b/drivers/mtd/maps/physmap_of.c index c1d21cb501ca..e48930424091 100644 --- a/drivers/mtd/maps/physmap_of.c +++ b/drivers/mtd/maps/physmap_of.c @@ -47,14 +47,12 @@ static int of_flash_remove(struct platform_device *dev) return 0; dev_set_drvdata(&dev->dev, NULL); - if (info->cmtd != info->list[0].mtd) { + if (info->cmtd) { mtd_device_unregister(info->cmtd); - mtd_concat_destroy(info->cmtd); + if (info->cmtd != info->list[0].mtd) + mtd_concat_destroy(info->cmtd); } - if (info->cmtd) - mtd_device_unregister(info->cmtd); - for (i = 0; i < info->list_size; i++) { if (info->list[i].mtd) map_destroy(info->list[i].mtd);