net: ethernet: aeroflex: fix UAF in greth_of_remove
authorPavel Skripkin <paskripkin@gmail.com>
Fri, 18 Jun 2021 14:57:31 +0000 (17:57 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 14 Jul 2021 14:56:24 +0000 (16:56 +0200)
[ Upstream commit e3a5de6d81d8b2199935c7eb3f7d17a50a7075b7 ]

static int greth_of_remove(struct platform_device *of_dev)
{
...
struct greth_private *greth = netdev_priv(ndev);
...
unregister_netdev(ndev);
free_netdev(ndev);

of_iounmap(&of_dev->resource[0], greth->regs, resource_size(&of_dev->resource[0]));
...
}

greth is netdev private data, but it is used
after free_netdev(). It can cause use-after-free when accessing greth
pointer. So, fix it by moving free_netdev() after of_iounmap()
call.

Fixes: d4c41139df6e ("net: Add Aeroflex Gaisler 10/100/1G Ethernet MAC driver")
Signed-off-by: Pavel Skripkin <paskripkin@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/ethernet/aeroflex/greth.c

index 9c5891bbfe61afbd798efcad906e632b07ca38a3..f4f50b3a472e179620a776b031243ed005586838 100644 (file)
@@ -1539,10 +1539,11 @@ static int greth_of_remove(struct platform_device *of_dev)
        mdiobus_unregister(greth->mdio);
 
        unregister_netdev(ndev);
-       free_netdev(ndev);
 
        of_iounmap(&of_dev->resource[0], greth->regs, resource_size(&of_dev->resource[0]));
 
+       free_netdev(ndev);
+
        return 0;
 }