From: Dan Carpenter Date: Thu, 5 Aug 2010 22:21:26 +0000 (+0000) Subject: isdn: gigaset: use after free X-Git-Tag: v2.6.36-rc1~43^2~28 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=8bcfbd0af0f8ee50033091e75ab3d6b6e7fa8867;p=profile%2Fcommon%2Fkernel-common.git isdn: gigaset: use after free I moved the kfree(cb) below the dereferences. Signed-off-by: Dan Carpenter Signed-off-by: David S. Miller --- diff --git a/drivers/isdn/gigaset/bas-gigaset.c b/drivers/isdn/gigaset/bas-gigaset.c index 0ded364..707d9c9 100644 --- a/drivers/isdn/gigaset/bas-gigaset.c +++ b/drivers/isdn/gigaset/bas-gigaset.c @@ -1914,11 +1914,13 @@ static int gigaset_write_cmd(struct cardstate *cs, struct cmdbuf_t *cb) * The next command will reopen the AT channel automatically. */ if (cb->len == 3 && !memcmp(cb->buf, "+++", 3)) { - kfree(cb); rc = req_submit(cs->bcs, HD_CLOSE_ATCHANNEL, 0, BAS_TIMEOUT); if (cb->wake_tasklet) tasklet_schedule(cb->wake_tasklet); - return rc < 0 ? rc : cb->len; + if (!rc) + rc = cb->len; + kfree(cb); + return rc; } spin_lock_irqsave(&cs->cmdlock, flags);