diff options
| author | James Smart <james.smart@broadcom.com> | 2020-10-20 13:27:13 -0700 | 
|---|---|---|
| committer | Martin K. Petersen <martin.petersen@oracle.com> | 2020-10-26 21:42:38 -0400 | 
| commit | e5785d3ec32f5f44dd88cd7b398e496742630469 (patch) | |
| tree | 676222a5acd4e440914bc4840e4d0e7ccbfda8b1 /drivers/scsi/lpfc | |
| parent | e7dab164a9aa457f89d4528452bdfc3e15ac98b6 (diff) | |
| download | linux-e5785d3ec32f5f44dd88cd7b398e496742630469.tar.bz2 | |
scsi: lpfc: Re-fix use after free in lpfc_rq_buf_free()
Commit 9816ef6ecbc1 ("scsi: lpfc: Use after free in lpfc_rq_buf_free()")
was made to correct a use after free condition in lpfc_rq_buf_free().
Unfortunately, a subsequent patch cut on a tree without the fix
inadvertently reverted the fix.
Put the fix back: Move the freeing of the rqb_entry to after the print
function that references it.
Link: https://lore.kernel.org/r/20201020202719.54726-4-james.smart@broadcom.com
Fixes: 411de511c694 ("scsi: lpfc: Fix RQ empty firmware trap")
Cc: <stable@vger.kernel.org> # v4.17+
Signed-off-by: James Smart <james.smart@broadcom.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Diffstat (limited to 'drivers/scsi/lpfc')
| -rw-r--r-- | drivers/scsi/lpfc/lpfc_mem.c | 2 | 
1 files changed, 1 insertions, 1 deletions
| diff --git a/drivers/scsi/lpfc/lpfc_mem.c b/drivers/scsi/lpfc/lpfc_mem.c index 79386e294fb9..be54fbf5146f 100644 --- a/drivers/scsi/lpfc/lpfc_mem.c +++ b/drivers/scsi/lpfc/lpfc_mem.c @@ -721,7 +721,6 @@ lpfc_rq_buf_free(struct lpfc_hba *phba, struct lpfc_dmabuf *mp)  	drqe.address_hi = putPaddrHigh(rqb_entry->dbuf.phys);  	rc = lpfc_sli4_rq_put(rqb_entry->hrq, rqb_entry->drq, &hrqe, &drqe);  	if (rc < 0) { -		(rqbp->rqb_free_buffer)(phba, rqb_entry);  		lpfc_printf_log(phba, KERN_ERR, LOG_INIT,  				"6409 Cannot post to HRQ %d: %x %x %x "  				"DRQ %x %x\n", @@ -731,6 +730,7 @@ lpfc_rq_buf_free(struct lpfc_hba *phba, struct lpfc_dmabuf *mp)  				rqb_entry->hrq->entry_count,  				rqb_entry->drq->host_index,  				rqb_entry->drq->hba_index); +		(rqbp->rqb_free_buffer)(phba, rqb_entry);  	} else {  		list_add_tail(&rqb_entry->hbuf.list, &rqbp->rqb_buffer_list);  		rqbp->buffer_count++; |