crypto: qce - fix uaf on qce_aead_register_one
authorChengfeng Ye <cyeaa@connect.ust.hk>
Thu, 4 Nov 2021 13:28:07 +0000 (06:28 -0700)
committerHerbert Xu <herbert@gondor.apana.org.au>
Sat, 20 Nov 2021 04:02:08 +0000 (15:02 +1100)
Pointer alg points to sub field of tmpl, it
is dereferenced after tmpl is freed. Fix
this by accessing alg before free tmpl.

Fixes: 9363efb4 ("crypto: qce - Add support for AEAD algorithms")
Signed-off-by: Chengfeng Ye <cyeaa@connect.ust.hk>
Acked-by: Thara Gopinath <thara.gopinath@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
drivers/crypto/qce/aead.c

index 290e244..97a5301 100644 (file)
@@ -802,8 +802,8 @@ static int qce_aead_register_one(const struct qce_aead_def *def, struct qce_devi
 
        ret = crypto_register_aead(alg);
        if (ret) {
-               kfree(tmpl);
                dev_err(qce->dev, "%s registration failed\n", alg->base.cra_name);
+               kfree(tmpl);
                return ret;
        }