Linux ACPI
 help / color / mirror / Atom feed
* [patch] dereference after kfree()
@ 2009-04-02  5:29 Dan Carpenter
  2009-04-03 16:48 ` Len Brown
  0 siblings, 1 reply; 2+ messages in thread
From: Dan Carpenter @ 2009-04-02  5:29 UTC (permalink / raw)
  To: shaohua.li, linux-acpi

dock_remove() calls kfree() on dock_station so we should use 
list_for_each_entry_safe() to avoid dereferencing freed memory.

Found by smatch (http://repo.or.cz/w/smatch.git/).  Compile tested.

regards,
dan carpenter

Signed-off-by: Dan Carpenter <error27@gmail.com>

--- orig/drivers/acpi/dock.c	2009-04-01 21:46:57.000000000 +0300
+++ devel/drivers/acpi/dock.c	2009-04-01 21:48:51.000000000 +0300
@@ -1146,9 +1146,10 @@
 static void __exit dock_exit(void)
 {
 	struct dock_station *dock_station;
+	struct dock_station *tmp;
 
 	unregister_acpi_bus_notifier(&dock_acpi_notifier);
-	list_for_each_entry(dock_station, &dock_stations, sibiling)
+	list_for_each_entry_safe(dock_station, tmp, &dock_stations, sibiling)
 		dock_remove(dock_station);
 }
 

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2009-04-03 16:48 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-04-02  5:29 [patch] dereference after kfree() Dan Carpenter
2009-04-03 16:48 ` Len Brown

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox