summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSudeep Holla <sudeep.holla@arm.com>2016-05-24 17:12:04 +0100
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2016-10-07 15:21:23 +0200
commit609442ec9a188e665da4897c6eace09a5afab791 (patch)
tree9445aba97034237093157ad73a19ba4ba3ecd2bd
parentb2c866c3d4bfa785fc082f0e3bd71317f231242c (diff)
downloadlwn-609442ec9a188e665da4897c6eace09a5afab791.tar.gz
lwn-609442ec9a188e665da4897c6eace09a5afab791.zip
mailbox: mailbox-test: set tdev->signal to NULL after freeing
commit 9ef3c5112139cc5c5666ee096e05bc1e00e94015 upstream. tdev->signal is not set NULL after it's freed. This will cause random exceptions when the stale pointer is accessed after tdev->signal is freed. Also, since tdev->signal allocation is skipped the next time it's written, this leads to continuous fault finally leading to the total death of the system. Fixes: d1c2f87c9a8f ("mailbox: mailbox-test: Prevent memory leak") Signed-off-by: Sudeep Holla <sudeep.holla@arm.com> Acked-by: Lee Jones <lee.jones@linaro.org> Signed-off-by: Jassi Brar <jaswinder.singh@linaro.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r--drivers/mailbox/mailbox-test.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/drivers/mailbox/mailbox-test.c b/drivers/mailbox/mailbox-test.c
index 58d04726cdd7..9ca96e9db6bf 100644
--- a/drivers/mailbox/mailbox-test.c
+++ b/drivers/mailbox/mailbox-test.c
@@ -133,6 +133,7 @@ static ssize_t mbox_test_message_write(struct file *filp,
out:
kfree(tdev->signal);
kfree(tdev->message);
+ tdev->signal = NULL;
return ret < 0 ? ret : count;
}