summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAlexandra Winter <wintera@linux.ibm.com>2026-09-02 16:37:33 +0200
committerJakub Kicinski <kuba@kernel.org>2026-09-04 16:12:36 -0700
commit907a56ab3eb8a58500a58daa76087f17bb2b6826 (patch)
tree257860ede5dc6518ced980ed654adebd92e35ca5
parent1668a31e3b1ad358d981ddb6dbd3db1fe0533621 (diff)
downloadlinux-next-907a56ab3eb8a58500a58daa76087f17bb2b6826.tar.gz
linux-next-907a56ab3eb8a58500a58daa76087f17bb2b6826.zip
s390/ism: folio_put() after error
dmb->cpu_addr was allocated via folio_alloc(). Use folio_put() instead of kfree() in the error exit of ism_alloc_dmb() to avoid slab allocator corruption. While at it, reset dmb->cpu_addr after folio_put to avoid unintentional UAF by future callers. Fixes: 83781384a96b ("s390/ism: Properly fix receive message buffer allocation") Signed-off-by: Alexandra Winter <wintera@linux.ibm.com> Reviewed-by: Gerd Bayer <gbayer@linux.ibm.com> Link: https://patch.msgid.link/20260902143733.433574-1-wintera@linux.ibm.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
-rw-r--r--drivers/s390/net/ism_drv.c4
1 files changed, 3 insertions, 1 deletions
diff --git a/drivers/s390/net/ism_drv.c b/drivers/s390/net/ism_drv.c
index 242da20f27e0..035b233abb4e 100644
--- a/drivers/s390/net/ism_drv.c
+++ b/drivers/s390/net/ism_drv.c
@@ -231,6 +231,7 @@ static void ism_free_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
dma_unmap_page(&ism->pdev->dev, dmb->dma_addr, dmb->dmb_len,
DMA_FROM_DEVICE);
folio_put(virt_to_folio(dmb->cpu_addr));
+ dmb->cpu_addr = NULL;
}
static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
@@ -274,7 +275,8 @@ static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
return 0;
out_free:
- kfree(dmb->cpu_addr);
+ folio_put(folio);
+ dmb->cpu_addr = NULL;
out_bit:
clear_bit(dmb->idx, ism->sba_bitmap);
return rc;