]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
net: davicom: fix UAF in dm9000_drv_remove
authorChenyuan Yang <chenyuan0y@gmail.com>
Thu, 23 Jan 2025 21:42:13 +0000 (15:42 -0600)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 13 Mar 2025 11:46:58 +0000 (12:46 +0100)
[ Upstream commit 19e65c45a1507a1a2926649d2db3583ed9d55fd9 ]

dm is netdev private data and it cannot be
used after free_netdev() call. Using dm after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of the
function.

This is similar to the issue fixed in commit
ad297cd2db89 ("net: qcom/emac: fix UAF in emac_remove").

This bug is detected by our static analysis tool.

Fixes: cf9e60aa69ae ("net: davicom: Fix regulator not turned off on driver removal")
Signed-off-by: Chenyuan Yang <chenyuan0y@gmail.com>
CC: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Link: https://patch.msgid.link/20250123214213.623518-1-chenyuan0y@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/ethernet/davicom/dm9000.c

index afc4a103c5080ff275a9abbbda912d77c456afb5..79aef6b368836c28194c39bbce73c78bc1e8f160 100644 (file)
@@ -1779,10 +1779,11 @@ dm9000_drv_remove(struct platform_device *pdev)
 
        unregister_netdev(ndev);
        dm9000_release_board(pdev, dm);
-       free_netdev(ndev);              /* free device structure */
        if (dm->power_supply)
                regulator_disable(dm->power_supply);
 
+       free_netdev(ndev);              /* free device structure */
+
        dev_dbg(&pdev->dev, "released and freed device\n");
        return 0;
 }