diff options
| author | Dinh Nguyen <dinguyen@kernel.org> | 2026-09-11 07:06:27 -0500 |
|---|---|---|
| committer | Borislav Petkov (AMD) <bp@alien8.de> | 2026-09-25 18:16:49 -0700 |
| commit | eef3b67f9c6782127163b631c9043011a68016e2 (patch) | |
| tree | 9e39415d54f6aef8df1f7add350241105a2fbc97 /scripts/Makefile.lib | |
| parent | 3e4a10a4718e3d963ee4d6c5f26bc5ad57c1d2b1 (diff) | |
| download | linux-stable-eef3b67f9c6782127163b631c9043011a68016e2.tar.gz linux-stable-eef3b67f9c6782127163b631c9043011a68016e2.zip | |
EDAC/altera: Fix use-after-free in error paths
In both altr_edac_a10_device_add() and altr_portb_setup(), the error path
freed the dci structure before releasing the devres group. Since the managed
single and double bit IRQ handlers use altdev(dci->pvt_info) as their data, an
IRQ firing between freeing dci and unregistering the IRQs could dereference
the freed memory.
Release the devres group first so the managed IRQs are unregistered
before the dci structure is freed.
Fixes: 911049845d70 ("EDAC, altera: Add Arria10 SD-MMC EDAC support")
Fixes: 588cb03ea208 ("EDAC, altera: Add Arria10 L2 Cache ECC handling")
Closes: https://sashiko.dev/#/patchset/20260719211238.589402-1-rosenp%40gmail.com
Assisted-by: LLM
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Cc: stable@vger.kernel.org ## 6.18+
Link: https://patch.msgid.link/20260911120627.2634225-5-dinguyen@kernel.org
Diffstat (limited to 'scripts/Makefile.lib')
0 files changed, 0 insertions, 0 deletions
