Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

scsi: elx: libefc: Fix potential use after free in efc_nport_vport_del()

The kref_put() function will call nport->release if the refcount drops to
zero. The nport->release release function is _efc_nport_free() which frees
"nport". But then we dereference "nport" on the next line which is a use
after free. Re-order these lines to avoid the use after free.

Fixes: fcd427303eb9 ("scsi: elx: libefc: SLI and FC PORT state machine interfaces")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://lore.kernel.org/r/b666ab26-6581-4213-9a3d-32a9147f0399@stanley.mountain
Reviewed-by: Daniel Wagner <dwagner@suse.de>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>

authored by

Dan Carpenter and committed by
Martin K. Petersen
2e4b02fa 89835a58

+1 -1
+1 -1
drivers/scsi/elx/libefc/efc_nport.c
··· 705 705 spin_lock_irqsave(&efc->lock, flags); 706 706 list_for_each_entry(nport, &domain->nport_list, list_entry) { 707 707 if (nport->wwpn == wwpn && nport->wwnn == wwnn) { 708 - kref_put(&nport->ref, nport->release); 709 708 /* Shutdown this NPORT */ 710 709 efc_sm_post_event(&nport->sm, EFC_EVT_SHUTDOWN, NULL); 710 + kref_put(&nport->ref, nport->release); 711 711 break; 712 712 } 713 713 }