Commit 1142751d authored by Dan Carpenter's avatar Dan Carpenter Committed by Liao Chen
Browse files

scsi: elx: libefc: Fix potential use after free in efc_nport_vport_del()

stable inclusion
from stable-v6.6.54
commit baeb8628ab7f4577740f00e439d3fdf7c876b0ff
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAYQS6
CVE: CVE-2024-49852

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=baeb8628ab7f4577740f00e439d3fdf7c876b0ff



--------------------------------

[ Upstream commit 2e4b02fad094976763af08fec2c620f4f8edd9ae ]

The kref_put() function will call nport->release if the refcount drops to
zero.  The nport->release release function is _efc_nport_free() which frees
"nport".  But then we dereference "nport" on the next line which is a use
after free.  Re-order these lines to avoid the use after free.

Fixes: fcd42730 ("scsi: elx: libefc: SLI and FC PORT state machine interfaces")
Signed-off-by: default avatarDan Carpenter <dan.carpenter@linaro.org>
Link: https://lore.kernel.org/r/b666ab26-6581-4213-9a3d-32a9147f0399@stanley.mountain


Reviewed-by: default avatarDaniel Wagner <dwagner@suse.de>
Signed-off-by: default avatarMartin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarLiao Chen <liaochen4@huawei.com>
parent e7bc7968
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -705,9 +705,9 @@ efc_nport_vport_del(struct efc *efc, struct efc_domain *domain,
	spin_lock_irqsave(&efc->lock, flags);
	list_for_each_entry(nport, &domain->nport_list, list_entry) {
		if (nport->wwpn == wwpn && nport->wwnn == wwnn) {
			kref_put(&nport->ref, nport->release);
			/* Shutdown this NPORT */
			efc_sm_post_event(&nport->sm, EFC_EVT_SHUTDOWN, NULL);
			kref_put(&nport->ref, nport->release);
			break;
		}
	}