net: ethernet: aeroflex: fix UAF in greth_of_remove
authorPavel Skripkin <paskripkin@gmail.com>
Fri, 18 Jun 2021 14:57:31 +0000 (17:57 +0300)
committerDavid S. Miller <davem@davemloft.net>
Sat, 19 Jun 2021 18:45:10 +0000 (11:45 -0700)
static int greth_of_remove(struct platform_device *of_dev)
{
...
struct greth_private *greth = netdev_priv(ndev);
...
unregister_netdev(ndev);
free_netdev(ndev);

of_iounmap(&of_dev->resource[0], greth->regs, resource_size(&of_dev->resource[0]));
...
}

greth is netdev private data, but it is used
after free_netdev(). It can cause use-after-free when accessing greth
pointer. So, fix it by moving free_netdev() after of_iounmap()
call.

Fixes: d4c41139df6e ("net: Add Aeroflex Gaisler 10/100/1G Ethernet MAC driver")
Signed-off-by: Pavel Skripkin <paskripkin@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
drivers/net/ethernet/aeroflex/greth.c

index d77fafb..c560ad0 100644 (file)
@@ -1539,10 +1539,11 @@ static int greth_of_remove(struct platform_device *of_dev)
        mdiobus_unregister(greth->mdio);
 
        unregister_netdev(ndev);
-       free_netdev(ndev);
 
        of_iounmap(&of_dev->resource[0], greth->regs, resource_size(&of_dev->resource[0]));
 
+       free_netdev(ndev);
+
        return 0;
 }