From: Hannes Reinecke Date: Tue, 8 Jan 2019 11:46:58 +0000 (+0100) Subject: nvme-multipath: zero out ANA log buffer X-Git-Tag: v5.0-rc2~10^2~5^2~3 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=c7055fd15ff46d92eb0dd1c16a4fe010d58224c8;p=users%2Fjedix%2Flinux-maple.git nvme-multipath: zero out ANA log buffer When nvme_init_identify() fails the ANA log buffer is deallocated but _not_ set to NULL. This can cause double free oops when this controller is deleted without ever being reconnected. Signed-off-by: Hannes Reinecke Signed-off-by: Christoph Hellwig --- diff --git a/drivers/nvme/host/multipath.c b/drivers/nvme/host/multipath.c index 183ec17ba067..df4b3a6db51b 100644 --- a/drivers/nvme/host/multipath.c +++ b/drivers/nvme/host/multipath.c @@ -570,6 +570,7 @@ int nvme_mpath_init(struct nvme_ctrl *ctrl, struct nvme_id_ctrl *id) return 0; out_free_ana_log_buf: kfree(ctrl->ana_log_buf); + ctrl->ana_log_buf = NULL; out: return error; } @@ -577,5 +578,6 @@ out: void nvme_mpath_uninit(struct nvme_ctrl *ctrl) { kfree(ctrl->ana_log_buf); + ctrl->ana_log_buf = NULL; }