From: Pavel Skripkin <hidden> Date: 2021-07-09 14:24:30
adpt is netdev private data and it cannot be
used after free_netdev() call. Using adpt after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of the
function.
Fixes: 54e19bc74f33 ("net: qcom/emac: do not use devm on internal phy pdev")
Signed-off-by: Pavel Skripkin <redacted>
---
drivers/net/ethernet/qualcomm/emac/emac.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
Hello:
This patch was applied to netdev/net.git (refs/heads/master):
On Fri, 9 Jul 2021 17:24:18 +0300 you wrote:
adpt is netdev private data and it cannot be
used after free_netdev() call. Using adpt after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of the
function.
Fixes: 54e19bc74f33 ("net: qcom/emac: do not use devm on internal phy pdev")
Signed-off-by: Pavel Skripkin <redacted>
[...]
From: Timur Tabi <timur@kernel.org> Date: 2021-07-10 05:03:06
On Fri, Jul 9, 2021 at 9:24 AM Pavel Skripkin [off-list ref] wrote:
adpt is netdev private data and it cannot be
used after free_netdev() call. Using adpt after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of the
function.
Please spell out what "UAF" means, thanks. If you fix that, then
Acked-by: Timur Tabi <timur@kernel.org>
Thanks.
From: Pavel Skripkin <hidden> Date: 2021-07-10 06:57:35
On Sat, 10 Jul 2021 00:02:26 -0500
Timur Tabi [off-list ref] wrote:
On Fri, Jul 9, 2021 at 9:24 AM Pavel Skripkin [off-list ref]
wrote:
quoted
adpt is netdev private data and it cannot be
used after free_netdev() call. Using adpt after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of the
function.
Please spell out what "UAF" means, thanks. If you fix that, then
Acked-by: Timur Tabi <timur@kernel.org>
Thanks.
Hi, Timur!
Thank you for feedback.
David has already applied this pacth. So, should I send v2 or maybe
revert + v2? I haven't been in such situations yet :)
With regards,
Pavel Skripkin