cifs: fix use after free for iface while disabling secondary channels
[ Upstream commit a15ccef82d3de9a37dc25898c60a394209368dc8 ] We were deferencing iface after it has been released. Fix is to release after all dereference instances have been encountered. Signed-off-by: Ritvik Budhiraja <rbudhiraja@microsoft.com> Reported-by: kernel test robot <lkp@intel.com> Reported-by: Dan Carpenter <error27@gmail.com> Closes: https://lore.kernel.org/r/202311110815.UJaeU3Tt-lkp@intel.com/ Signed-off-by: Steve French <stfrench@microsoft.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
parent
bb536892da
commit
a7b537b3be
|
@ -337,10 +337,10 @@ cifs_disable_secondary_channels(struct cifs_ses *ses)
|
|||
|
||||
if (iface) {
|
||||
spin_lock(&ses->iface_lock);
|
||||
kref_put(&iface->refcount, release_iface);
|
||||
iface->num_channels--;
|
||||
if (iface->weight_fulfilled)
|
||||
iface->weight_fulfilled--;
|
||||
kref_put(&iface->refcount, release_iface);
|
||||
spin_unlock(&ses->iface_lock);
|
||||
}
|
||||
|
||||
|
|
Loading…
Reference in New Issue