From: Jiang Liu Date: Thu, 6 Jun 2013 16:07:22 +0000 (+0800) Subject: zram: avoid invalid memory access in zram_exit() X-Git-Tag: upstream/snapshot3+hdmi~4847^2~230 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=6030ea9b35971a4200062f010341ab832e878ac9;p=platform%2Fadaptation%2Frenesas_rcar%2Frenesas_kernel.git zram: avoid invalid memory access in zram_exit() Memory for zram->disk object may have already been freed after returning from destroy_device(zram), then it's unsafe for zram_reset_device(zram) to access zram->disk again. We can't solve this bug by flipping the order of destroy_device(zram) and zram_reset_device(zram), that will cause deadlock issues to the zram sysfs handler. So fix it by holding an extra reference to zram->disk before calling destroy_device(zram). Signed-off-by: Jiang Liu Cc: stable@vger.kernel.org Signed-off-by: Greg Kroah-Hartman --- diff --git a/drivers/staging/zram/zram_drv.c b/drivers/staging/zram/zram_drv.c index d628bd3..9057520 100644 --- a/drivers/staging/zram/zram_drv.c +++ b/drivers/staging/zram/zram_drv.c @@ -727,8 +727,10 @@ static void __exit zram_exit(void) for (i = 0; i < num_devices; i++) { zram = &zram_devices[i]; + get_disk(zram->disk); destroy_device(zram); zram_reset_device(zram); + put_disk(zram->disk); } unregister_blkdev(zram_major, "zram");