diff options
author | Dan Carpenter <error27@gmail.com> | 2010-08-06 02:21:26 +0400 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2010-08-08 10:04:12 +0400 |
commit | 8bcfbd0af0f8ee50033091e75ab3d6b6e7fa8867 (patch) | |
tree | 10b10edd8ecc8020e7ae2182ddf7fa06761523c6 /drivers/isdn/gigaset | |
parent | 7e27a0aeb98d53539bdc38384eee899d6db62617 (diff) | |
download | linux-8bcfbd0af0f8ee50033091e75ab3d6b6e7fa8867.tar.xz |
isdn: gigaset: use after free
I moved the kfree(cb) below the dereferences.
Signed-off-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'drivers/isdn/gigaset')
-rw-r--r-- | drivers/isdn/gigaset/bas-gigaset.c | 6 |
1 files changed, 4 insertions, 2 deletions
diff --git a/drivers/isdn/gigaset/bas-gigaset.c b/drivers/isdn/gigaset/bas-gigaset.c index 0ded3640b926..707d9c94cf9e 100644 --- a/drivers/isdn/gigaset/bas-gigaset.c +++ b/drivers/isdn/gigaset/bas-gigaset.c @@ -1914,11 +1914,13 @@ static int gigaset_write_cmd(struct cardstate *cs, struct cmdbuf_t *cb) * The next command will reopen the AT channel automatically. */ if (cb->len == 3 && !memcmp(cb->buf, "+++", 3)) { - kfree(cb); rc = req_submit(cs->bcs, HD_CLOSE_ATCHANNEL, 0, BAS_TIMEOUT); if (cb->wake_tasklet) tasklet_schedule(cb->wake_tasklet); - return rc < 0 ? rc : cb->len; + if (!rc) + rc = cb->len; + kfree(cb); + return rc; } spin_lock_irqsave(&cs->cmdlock, flags); |