Skip to content

Commit

Permalink
net: davicom: fix UAF in dm9000_drv_remove
Browse files Browse the repository at this point in the history
[ Upstream commit 19e65c4 ]

dm is netdev private data and it cannot be
used after free_netdev() call. Using dm after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of the
function.

This is similar to the issue fixed in commit
ad297cd ("net: qcom/emac: fix UAF in emac_remove").

This bug is detected by our static analysis tool.

Fixes: cf9e60a ("net: davicom: Fix regulator not turned off on driver removal")
Signed-off-by: Chenyuan Yang <chenyuan0y@gmail.com>
CC: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Link: https://patch.msgid.link/20250123214213.623518-1-chenyuan0y@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
  • Loading branch information
Chenyuan Yang authored and Greg Kroah-Hartman committed Mar 13, 2025
1 parent d9a7079 commit a53cb72
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion drivers/net/ethernet/davicom/dm9000.c
Original file line number Diff line number Diff line change
Expand Up @@ -1779,10 +1779,11 @@ dm9000_drv_remove(struct platform_device *pdev)

unregister_netdev(ndev);
dm9000_release_board(pdev, dm);
free_netdev(ndev); /* free device structure */
if (dm->power_supply)
regulator_disable(dm->power_supply);

free_netdev(ndev); /* free device structure */

dev_dbg(&pdev->dev, "released and freed device\n");
return 0;
}
Expand Down

0 comments on commit a53cb72

Please sign in to comment.