Skip to content

Commit 7f138de

Browse files
lgs2513andy-shev
authored andcommitted
auxdisplay: line-display: fix NULL dereference in linedisp_release
linedisp_release() currently retrieves the enclosing struct linedisp via to_linedisp(). That lookup depends on the attachment list, but the attachment may already have been removed before put_device() invokes the release callback. This can happen in linedisp_unregister(), and can also be reached from some linedisp_register() error paths. In that case, to_linedisp() returns NULL and linedisp_release() dereferences it while freeing the display resources. The struct device released here is the embedded linedisp->dev used by linedisp_register(), so retrieve the enclosing object directly with container_of() instead. Fixes: 66c9380 ("auxdisplay: linedisp: encapsulate container_of usage within to_linedisp") Cc: stable@vger.kernel.org Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com> Reviewed-by: Geert Uytterhoeven <geert@linux-m68k.org> Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
1 parent 995a418 commit 7f138de

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

drivers/auxdisplay/line-display.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -365,7 +365,7 @@ static DEFINE_IDA(linedisp_id);
365365

366366
static void linedisp_release(struct device *dev)
367367
{
368-
struct linedisp *linedisp = to_linedisp(dev);
368+
struct linedisp *linedisp = container_of(dev, struct linedisp, dev);
369369

370370
kfree(linedisp->map);
371371
kfree(linedisp->message);

0 commit comments

Comments
 (0)