From: Julia Lawall Date: Fri, 23 Dec 2011 13:02:55 +0000 (+0100) Subject: drivers/usb/class/cdc-acm.c: clear dangling pointer X-Git-Tag: v3.3-rc1~153^2~4 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=e7c8e8605d0bafc705ff27f9da98a1668427cc0f;p=users%2Fhch%2Fmisc.git drivers/usb/class/cdc-acm.c: clear dangling pointer On some failures, the country_code field of an acm structure is freed without freeing the acm structure itself. Elsewhere, operations including memcpy and kfree are performed on the country_code field. The patch sets the country_code field to NULL when it is freed, and likewise sets the country_code_size field to 0. Signed-off-by: Julia Lawall Acked-by: Oliver Neukum Cc: stable Signed-off-by: Greg Kroah-Hartman --- diff --git a/drivers/usb/class/cdc-acm.c b/drivers/usb/class/cdc-acm.c index d9d9340abe60..57f2e1032086 100644 --- a/drivers/usb/class/cdc-acm.c +++ b/drivers/usb/class/cdc-acm.c @@ -1230,6 +1230,8 @@ made_compressed_probe: i = device_create_file(&intf->dev, &dev_attr_wCountryCodes); if (i < 0) { kfree(acm->country_codes); + acm->country_codes = NULL; + acm->country_code_size = 0; goto skip_countries; } @@ -1238,6 +1240,8 @@ made_compressed_probe: if (i < 0) { device_remove_file(&intf->dev, &dev_attr_wCountryCodes); kfree(acm->country_codes); + acm->country_codes = NULL; + acm->country_code_size = 0; goto skip_countries; } }