Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

Input: synaptics-rmi4 - fix use after free in rmi_unregister_function()

The put_device() calls rmi_release_function() which frees "fn" so the
dereference on the next line "fn->num_of_irqs" is a use after free.
Move the put_device() to the end to fix this.

Fixes: 24d28e4f1271 ("Input: synaptics-rmi4 - convert irq distribution to irq_domain")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://lore.kernel.org/r/706efd36-7561-42f3-adfa-dd1d0bd4f5a1@moroto.mountain
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>

authored by

Dan Carpenter and committed by
Dmitry Torokhov
eb988e46 290e44ba

+1 -1
+1 -1
drivers/input/rmi4/rmi_bus.c
··· 277 277 278 278 device_del(&fn->dev); 279 279 of_node_put(fn->dev.of_node); 280 - put_device(&fn->dev); 281 280 282 281 for (i = 0; i < fn->num_of_irqs; i++) 283 282 irq_dispose_mapping(fn->irq[i]); 284 283 284 + put_device(&fn->dev); 285 285 } 286 286 287 287 /**