lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 17 Aug 2020 17:14:16 +0200 From: Greg Kroah-Hartman <gregkh@...uxfoundation.org> To: linux-kernel@...r.kernel.org Cc: Greg Kroah-Hartman <gregkh@...uxfoundation.org>, stable@...r.kernel.org, Evgeny Novikov <novikov@...ras.ru>, Jani Nikula <jani.nikula@...el.com>, Mike Rapoport <rppt@...ux.ibm.com>, Daniel Vetter <daniel.vetter@...ll.ch>, Andrew Morton <akpm@...ux-foundation.org>, Bartlomiej Zolnierkiewicz <b.zolnierkie@...sung.com>, Sasha Levin <sashal@...nel.org> Subject: [PATCH 5.4 055/270] video: fbdev: neofb: fix memory leak in neo_scan_monitor() From: Evgeny Novikov <novikov@...ras.ru> [ Upstream commit edcb3895a751c762a18d25c8d9846ce9759ed7e1 ] neofb_probe() calls neo_scan_monitor() that can successfully allocate a memory for info->monspecs.modedb and proceed to case 0x03. There it does not free the memory and returns -1. neofb_probe() goes to label err_scan_monitor, thus, it does not free this memory through calling fb_destroy_modedb() as well. We can not go to label err_init_hw since neo_scan_monitor() can fail during memory allocation. So, the patch frees the memory directly for case 0x03. Found by Linux Driver Verification project (linuxtesting.org). Signed-off-by: Evgeny Novikov <novikov@...ras.ru> Cc: Jani Nikula <jani.nikula@...el.com> Cc: Mike Rapoport <rppt@...ux.ibm.com> Cc: Daniel Vetter <daniel.vetter@...ll.ch> Cc: Andrew Morton <akpm@...ux-foundation.org> Signed-off-by: Bartlomiej Zolnierkiewicz <b.zolnierkie@...sung.com> Link: https://patchwork.freedesktop.org/patch/msgid/20200630195451.18675-1-novikov@ispras.ru Signed-off-by: Sasha Levin <sashal@...nel.org> --- drivers/video/fbdev/neofb.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/video/fbdev/neofb.c b/drivers/video/fbdev/neofb.c index b770946a09206..76464000933d8 100644 --- a/drivers/video/fbdev/neofb.c +++ b/drivers/video/fbdev/neofb.c @@ -1820,6 +1820,7 @@ static int neo_scan_monitor(struct fb_info *info) #else printk(KERN_ERR "neofb: Only 640x480, 800x600/480 and 1024x768 panels are currently supported\n"); + kfree(info->monspecs.modedb); return -1; #endif default: -- 2.25.1
Powered by blists - more mailing lists