ACPI / Battery: avoid acpi_battery_add() use-after-free
When acpi_battery_add_fs() fails the error handling code does not clean up completely. Moreover, it does not return resulting in a use-after-free. Signed-off-by: Stefan Hajnoczi <stefanha@linux.vnet.ibm.com> Signed-off-by: Len Brown <len.brown@intel.com>
This commit is contained in:
committed by
Len Brown
parent
9c921c22a7
commit
e80bba4b51
@@ -986,21 +986,27 @@ static int acpi_battery_add(struct acpi_device *device)
|
|||||||
#ifdef CONFIG_ACPI_PROCFS_POWER
|
#ifdef CONFIG_ACPI_PROCFS_POWER
|
||||||
result = acpi_battery_add_fs(device);
|
result = acpi_battery_add_fs(device);
|
||||||
#endif
|
#endif
|
||||||
if (!result) {
|
if (result) {
|
||||||
printk(KERN_INFO PREFIX "%s Slot [%s] (battery %s)\n",
|
|
||||||
ACPI_BATTERY_DEVICE_NAME, acpi_device_bid(device),
|
|
||||||
device->status.battery_present ? "present" : "absent");
|
|
||||||
} else {
|
|
||||||
#ifdef CONFIG_ACPI_PROCFS_POWER
|
#ifdef CONFIG_ACPI_PROCFS_POWER
|
||||||
acpi_battery_remove_fs(device);
|
acpi_battery_remove_fs(device);
|
||||||
#endif
|
#endif
|
||||||
kfree(battery);
|
goto fail;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
printk(KERN_INFO PREFIX "%s Slot [%s] (battery %s)\n",
|
||||||
|
ACPI_BATTERY_DEVICE_NAME, acpi_device_bid(device),
|
||||||
|
device->status.battery_present ? "present" : "absent");
|
||||||
|
|
||||||
battery->pm_nb.notifier_call = battery_notify;
|
battery->pm_nb.notifier_call = battery_notify;
|
||||||
register_pm_notifier(&battery->pm_nb);
|
register_pm_notifier(&battery->pm_nb);
|
||||||
|
|
||||||
return result;
|
return result;
|
||||||
|
|
||||||
|
fail:
|
||||||
|
sysfs_remove_battery(battery);
|
||||||
|
mutex_destroy(&battery->lock);
|
||||||
|
kfree(battery);
|
||||||
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
static int acpi_battery_remove(struct acpi_device *device, int type)
|
static int acpi_battery_remove(struct acpi_device *device, int type)
|
||||||
|
Reference in New Issue
Block a user