diff options
| author | Julia Lawall <julia@diku.dk> | 2010-07-30 17:17:28 +0200 | 
|---|---|---|
| committer | Russell King <rmk+kernel@arm.linux.org.uk> | 2010-07-30 23:19:30 +0100 | 
| commit | f2d2420bbf4bb125ea5f2e1573d4da6b668fc78a (patch) | |
| tree | b6a074ce9a14e7fc1f99641bb3e47b83417f34eb /kernel/trace/ring_buffer.c | |
| parent | 74bc80931c8bc34d24545f992a35349ad548897c (diff) | |
SA1111: Eliminate use after free
__sa1111_remove always frees its argument, so the subsequent reference to
sachip->saved_state represents a use after free.  __sa1111_remove does not
appear to use the saved_state field, so the patch simply frees it first.
A simplified version of the semantic patch that finds this problem is as
follows: (http://coccinelle.lip6.fr/)
// <smpl>
@@
expression E,E2;
@@
__sa1111_remove(E)
...
(
  E = E2
|
* E
)
// </smpl>
Signed-off-by: Julia Lawall <julia@diku.dk>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Diffstat (limited to 'kernel/trace/ring_buffer.c')
0 files changed, 0 insertions, 0 deletions
