Linux ACPI
 help / color / mirror / Atom feed
* [2.6.28.y, 2.6.29.y PATCH] dock: fix dereference after kfree()
@ 2009-04-07  3:56 Len Brown
  0 siblings, 0 replies; only message in thread
From: Len Brown @ 2009-04-07  3:56 UTC (permalink / raw)
  To: stable; +Cc: linux-acpi

From: Dan Carpenter <error27@gmail.com>
Date: Thu, 2 Apr 2009 08:29:56 +0300
Subject: [PATCH] dock: fix dereference after kfree()

upstream f240729832dff3785104d950dad2d3ced4387f6d

dock_remove() calls kfree() on dock_station so we should use
list_for_each_entry_safe() to avoid dereferencing freed memory.

Found by smatch (http://repo.or.cz/w/smatch.git/).  Compile tested.

Signed-off-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Len Brown <len.brown@intel.com>
---
 drivers/acpi/dock.c |    3 ++-
 1 files changed, 2 insertions(+), 1 deletions(-)

diff --git a/drivers/acpi/dock.c b/drivers/acpi/dock.c
index 35094f2..8f62fa0 100644
--- a/drivers/acpi/dock.c
+++ b/drivers/acpi/dock.c
@@ -1146,9 +1146,10 @@ static int __init dock_init(void)
 static void __exit dock_exit(void)
 {
 	struct dock_station *dock_station;
+	struct dock_station *tmp;
 
 	unregister_acpi_bus_notifier(&dock_acpi_notifier);
-	list_for_each_entry(dock_station, &dock_stations, sibiling)
+	list_for_each_entry_safe(dock_station, tmp, &dock_stations, sibiling)
 		dock_remove(dock_station);
 }
 
-- 
1.6.2.2.446.gfbdc


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2009-04-07  3:56 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-04-07  3:56 [2.6.28.y, 2.6.29.y PATCH] dock: fix dereference after kfree() Len Brown

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox