Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

ACPI / memhotplug: Fix a stale pointer in error path

device->driver_data needs to be cleared when releasing its data,
mem_device, in an error path of acpi_memory_device_add().

The function evaluates the _CRS of memory device objects, and fails
when it gets an unexpected resource or cannot allocate memory. A
kernel crash or data corruption may occur when the kernel accesses
the stale pointer.

Signed-off-by: Toshi Kani <toshi.kani@hp.com>
Reviewed-by: Yasuaki Ishimatsu <isimatu.yasuaki@jp.fujitsu.com>
Cc: 2.6.32+ <stable@vger.kernel.org>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

authored by

Toshi Kani and committed by
Rafael J. Wysocki
d19f503e 8832f7e4

+1
+1
drivers/acpi/acpi_memhotplug.c
··· 323 323 /* Get the range from the _CRS */ 324 324 result = acpi_memory_get_device_resources(mem_device); 325 325 if (result) { 326 + device->driver_data = NULL; 326 327 kfree(mem_device); 327 328 return result; 328 329 }