net_dim_init_irq_moder() publishes the allocated object in
dev->irq_moder before copying the moderation profiles.  If kmemdup()
fails, the object is freed but the pointer is left dangling.
net_dim_free_irq_moder() treats a non-NULL irq_moder as live, so a
caller unwinding the failure path would use-after-free.

NULL the pointer after freeing it.  On error the device is left as if
initialization never happened.

Fixes: f750dfe825b90 ("ethtool: provide customized dim profile management")
Signed-off-by: Jianlin Shi <[email protected]>
---
 lib/dim/net_dim.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/lib/dim/net_dim.c b/lib/dim/net_dim.c
index d8d4f6553559..bf59deae6a29 100644
--- a/lib/dim/net_dim.c
+++ b/lib/dim/net_dim.c
@@ -141,6 +141,7 @@ int net_dim_init_irq_moder(struct net_device *dev, u8 
profile_flags,
        kfree(rxp);
 free_moder:
        kfree(moder);
+       dev->irq_moder = NULL;
        return -ENOMEM;
 }
 EXPORT_SYMBOL(net_dim_init_irq_moder);
-- 
2.43.0


Reply via email to