Commit de50f715 authored by Dan Carpenter's avatar Dan Carpenter Committed by Zhang Kunbo
Browse files

sh: intc: Fix use-after-free bug in register_intc_controller()

stable inclusion
from stable-v5.10.231
commit 971b4893457788e0e123ea552f0bb126a5300e61
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IBEAEH
CVE: CVE-2024-53165

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=971b4893457788e0e123ea552f0bb126a5300e61



--------------------------------

[ Upstream commit 63e72e551942642c48456a4134975136cdcb9b3c ]

In the error handling for this function, d is freed without ever
removing it from intc_list which would lead to a use after free.
To fix this, let's only add it to the list after everything has
succeeded.

Fixes: 2dcec7a9 ("sh: intc: set_irq_wake() support")
Signed-off-by: default avatarDan Carpenter <dan.carpenter@linaro.org>
Reviewed-by: default avatarJohn Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Signed-off-by: default avatarJohn Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarZhang Kunbo <zhangkunbo@huawei.com>
parent df71fa5a
Loading
Loading
Loading
Loading
+1 −1
Original line number Original line Diff line number Diff line
@@ -194,7 +194,6 @@ int __init register_intc_controller(struct intc_desc *desc)
		goto err0;
		goto err0;


	INIT_LIST_HEAD(&d->list);
	INIT_LIST_HEAD(&d->list);
	list_add_tail(&d->list, &intc_list);


	raw_spin_lock_init(&d->lock);
	raw_spin_lock_init(&d->lock);
	INIT_RADIX_TREE(&d->tree, GFP_ATOMIC);
	INIT_RADIX_TREE(&d->tree, GFP_ATOMIC);
@@ -380,6 +379,7 @@ int __init register_intc_controller(struct intc_desc *desc)


	d->skip_suspend = desc->skip_syscore_suspend;
	d->skip_suspend = desc->skip_syscore_suspend;


	list_add_tail(&d->list, &intc_list);
	nr_intc_controllers++;
	nr_intc_controllers++;


	return 0;
	return 0;