| From 2ff78c0c2b67120c8e503268da3f177cae2228a2 Mon Sep 17 00:00:00 2001 |
| From: Johan Hovold <jhovold@gmail.com> |
| Date: Thu, 13 May 2010 21:02:00 +0200 |
| Subject: USB: ir-usb: fix double free |
| |
| From: Johan Hovold <jhovold@gmail.com> |
| |
| commit 2ff78c0c2b67120c8e503268da3f177cae2228a2 upstream. |
| |
| If the user specifies a custom bulk buffer size we get a double free at |
| port release. |
| |
| Signed-off-by: Johan Hovold <jhovold@gmail.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de> |
| |
| --- |
| drivers/usb/serial/ir-usb.c | 2 ++ |
| 1 file changed, 2 insertions(+) |
| |
| --- a/drivers/usb/serial/ir-usb.c |
| +++ b/drivers/usb/serial/ir-usb.c |
| @@ -312,6 +312,7 @@ static int ir_open(struct tty_struct *tt |
| kfree(port->read_urb->transfer_buffer); |
| port->read_urb->transfer_buffer = buffer; |
| port->read_urb->transfer_buffer_length = buffer_size; |
| + port->bulk_in_buffer = buffer; |
| |
| buffer = kmalloc(buffer_size, GFP_KERNEL); |
| if (!buffer) { |
| @@ -321,6 +322,7 @@ static int ir_open(struct tty_struct *tt |
| kfree(port->write_urb->transfer_buffer); |
| port->write_urb->transfer_buffer = buffer; |
| port->write_urb->transfer_buffer_length = buffer_size; |
| + port->bulk_out_buffer = buffer; |
| port->bulk_out_size = buffer_size; |
| } |
| |