Forum | Documentation | Website | Blog

Skip to content
Snippets Groups Projects
Commit bd91b56c authored by Thomas Tai's avatar Thomas Tai Committed by Bjorn Helgaas
Browse files

PCI/AER: Work around use-after-free in pcie_do_fatal_recovery()

When an fatal error is received by a non-bridge device, the device is
removed, and pci_stop_and_remove_bus_device() deallocates the device
structure.  The freed device structure is used by subsequent code to send
uevents and print messages.

Hold a reference on the device until we're finished using it.  This is not
an ideal fix because pcie_do_fatal_recovery() should not use the device at
all after removing it, but that's too big a project for right now.

Fixes: 7e9084b3

 ("PCI/AER: Handle ERR_FATAL with removal and re-enumeration of devices")
Signed-off-by: default avatarThomas Tai <thomas.tai@oracle.com>
[bhelgaas: changelog, reduce get/put coverage]
Signed-off-by: default avatarBjorn Helgaas <bhelgaas@google.com>
parent 270ed733
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment