Skip to content

Commit

Permalink
mmc: card: fix potential null dereference of 'idata'
Browse files Browse the repository at this point in the history
When allocation of idata failed there was a null dereference. Also avoid
calling kfree where it isn't needed.

Signed-off-by: Vladimir Motyka <vladimir.motyka@gmail.com>
Signed-off-by: Chris Ball <cjb@laptop.org>
  • Loading branch information
Vladimir Motyka authored and Chris Ball committed May 25, 2011
1 parent cf2b5ee commit aea253e
Showing 1 changed file with 6 additions and 5 deletions.
11 changes: 6 additions & 5 deletions drivers/mmc/card/block.c
Original file line number Diff line number Diff line change
Expand Up @@ -237,24 +237,24 @@ static struct mmc_blk_ioc_data *mmc_blk_ioctl_copy_from_user(
idata = kzalloc(sizeof(*idata), GFP_KERNEL);
if (!idata) {
err = -ENOMEM;
goto copy_err;
goto out;
}

if (copy_from_user(&idata->ic, user, sizeof(idata->ic))) {
err = -EFAULT;
goto copy_err;
goto idata_err;
}

idata->buf_bytes = (u64) idata->ic.blksz * idata->ic.blocks;
if (idata->buf_bytes > MMC_IOC_MAX_BYTES) {
err = -EOVERFLOW;
goto copy_err;
goto idata_err;
}

idata->buf = kzalloc(idata->buf_bytes, GFP_KERNEL);
if (!idata->buf) {
err = -ENOMEM;
goto copy_err;
goto idata_err;
}

if (copy_from_user(idata->buf, (void __user *)(unsigned long)
Expand All @@ -267,9 +267,10 @@ static struct mmc_blk_ioc_data *mmc_blk_ioctl_copy_from_user(

copy_err:
kfree(idata->buf);
idata_err:
kfree(idata);
out:
return ERR_PTR(err);

}

static int mmc_blk_ioctl_cmd(struct block_device *bdev,
Expand Down

0 comments on commit aea253e

Please sign in to comment.