public inbox for linux-sh@vger.kernel.org
 help / color / mirror / Atom feed
From: Matt Fleming <matt@console-pimps.org>
To: linux-sh@vger.kernel.org
Subject: Re: Bug: access to already released memory
Date: Sun, 31 Jan 2010 11:55:27 +0000	[thread overview]
Message-ID: <m3vdeiqyj4.fsf@phlog.console-pimps.org> (raw)
In-Reply-To: <a328840c1001301356r14505614pbb4563754c6890ac@mail.gmail.com>

On Sat, 30 Jan 2010 22:56:30 +0100, Marek Skuczynski <mareksk7@gmail.com> wrote:
> Hello,
>    I have found two places where access to already released memory happens,
>    attaching patches.
> 
> Regards,
>   Marek
> From 1d0be80204871527e1e7757f4a009ce6f9ba0d73 Mon Sep 17 00:00:00 2001
> From: Marek Skuczynski <mareksk7@gmail.com>
> Date: Sat, 30 Jan 2010 22:27:41 +0100
> Subject: [PATCH 1/2] sh: Fix access to released memory in dwarf_unwinder_cleanup()
> 
> Signed-off-by: Marek Skuczynski <mareksk7@gmail.com>
> ---
>  arch/sh/kernel/dwarf.c |    8 ++++----
>  1 files changed, 4 insertions(+), 4 deletions(-)
> 
> diff --git a/arch/sh/kernel/dwarf.c b/arch/sh/kernel/dwarf.c
> index 3576b70..88d28ec 100644
> --- a/arch/sh/kernel/dwarf.c
> +++ b/arch/sh/kernel/dwarf.c
> @@ -892,18 +892,18 @@ static struct unwinder dwarf_unwinder = {
>  
>  static void dwarf_unwinder_cleanup(void)
>  {
> -	struct dwarf_cie *cie;
> -	struct dwarf_fde *fde;
> +	struct dwarf_cie *cie, *cie_tmp;
> +	struct dwarf_fde *fde, *fde_tmp;
>  
>  	/*
>  	 * Deallocate all the memory allocated for the DWARF unwinder.
>  	 * Traverse all the FDE/CIE lists and remove and free all the
>  	 * memory associated with those data structures.
>  	 */
> -	list_for_each_entry(cie, &dwarf_cie_list, link)
> +	list_for_each_entry_safe(cie, cie_tmp, &dwarf_cie_list, link)
>  		kfree(cie);
>  
> -	list_for_each_entry(fde, &dwarf_fde_list, link)
> +	list_for_each_entry_safe(fde, fde_tmp, &dwarf_fde_list, link)
>  		kfree(fde);
>  
>  	kmem_cache_destroy(dwarf_reg_cachep);
> -- 
> 1.6.4.2
> 

Good catch.

Acked-by: Matt Fleming <matt@console-pimps.org>

      parent reply	other threads:[~2010-01-31 11:55 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-01-30 21:56 Bug: access to already released memory Marek Skuczynski
2010-01-31  3:55 ` Paul Mundt
2010-01-31 11:55 ` Matt Fleming [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m3vdeiqyj4.fsf@phlog.console-pimps.org \
    --to=matt@console-pimps.org \
    --cc=linux-sh@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox