hidp bug concerning ctrl_sk sock
From: Karl Relton <hidden>
Date: 2012-12-06 21:04:21
From: Karl Relton <hidden>
Date: 2012-12-06 21:04:21
With reference to bug https://bugzilla.kernel.org/show_bug.cgi?id=50541 it seems to me that the hidp driver has a problem in the hidp_session() function. The sock structure pointed to by ctrl_sk is being freed from under the functions feet (as far as I can see), causing this function to crash. Shouldn't a lock_sock or sock_hold be necessary to keep the sock structure around until hidp_session has finished with it?