* [2.6.28.y, 2.6.29.y PATCH] dock: fix dereference after kfree()
@ 2009-04-07 3:56 Len Brown
0 siblings, 0 replies; only message in thread
From: Len Brown @ 2009-04-07 3:56 UTC (permalink / raw)
To: stable; +Cc: linux-acpi
From: Dan Carpenter <error27@gmail.com>
Date: Thu, 2 Apr 2009 08:29:56 +0300
Subject: [PATCH] dock: fix dereference after kfree()
upstream f240729832dff3785104d950dad2d3ced4387f6d
dock_remove() calls kfree() on dock_station so we should use
list_for_each_entry_safe() to avoid dereferencing freed memory.
Found by smatch (http://repo.or.cz/w/smatch.git/). Compile tested.
Signed-off-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Len Brown <len.brown@intel.com>
---
drivers/acpi/dock.c | 3 ++-
1 files changed, 2 insertions(+), 1 deletions(-)
diff --git a/drivers/acpi/dock.c b/drivers/acpi/dock.c
index 35094f2..8f62fa0 100644
--- a/drivers/acpi/dock.c
+++ b/drivers/acpi/dock.c
@@ -1146,9 +1146,10 @@ static int __init dock_init(void)
static void __exit dock_exit(void)
{
struct dock_station *dock_station;
+ struct dock_station *tmp;
unregister_acpi_bus_notifier(&dock_acpi_notifier);
- list_for_each_entry(dock_station, &dock_stations, sibiling)
+ list_for_each_entry_safe(dock_station, tmp, &dock_stations, sibiling)
dock_remove(dock_station);
}
--
1.6.2.2.446.gfbdc
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2009-04-07 3:56 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-04-07 3:56 [2.6.28.y, 2.6.29.y PATCH] dock: fix dereference after kfree() Len Brown
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox