[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <alpine.DEB.2.21.2107131853530.9461@angie.orcam.me.uk>
Date: Tue, 13 Jul 2021 18:59:54 +0200 (CEST)
From: "Maciej W. Rozycki" <macro@...am.me.uk>
To: Pavel Skripkin <paskripkin@...il.com>
cc: davem@...emloft.net, netdev@...r.kernel.org,
linux-kernel@...r.kernel.org
Subject: Re: [PATCH] net: fddi: fix UAF in fza_probe
On Tue, 13 Jul 2021, Pavel Skripkin wrote:
> fp is netdev private data and it cannot be
> used after free_netdev() call. Using fp after free_netdev()
> can cause UAF bug. Fix it by moving free_netdev() after error message.
Can you justify the lines for a better layout? The paragraph looks odd
to me in its current form.
> Fixes: 61414f5ec983 ("FDDI: defza: Add support for DEC FDDIcontroller 700
> TURBOchannel adapter")
> Signed-off-by: Pavel Skripkin <paskripkin@...il.com>
Otherwise LGTM. And a good catch, thank you!
Reviewed-by: Maciej W. Rozycki <macro@...am.me.uk>
Maciej
Powered by blists - more mailing lists