(master) synaptics: fix missing NULL check + open_slots double-free in DeviceInit() - #15
Open
metux wants to merge 1 commit into
Conversation
…nit() DeviceInit() checked priv->hwState and priv->local_hw_state for allocation failure but not the third SynapticsHwStateAlloc() call (priv->comm.hwState) -- SynapticsReset(), called right after, derefs it unconditionally. Separately, the 'fail' cleanup path used raw free() on hwState/ local_hw_state instead of SynapticsHwStateFree() (leaking their nested slot_state/mt_mask allocations), and freed priv->open_slots without resetting it to NULL. priv survives a failed DeviceInit() and SynapticsUnInit() later frees priv->open_slots again if it's still non-NULL, so this was a double-free on the open_slots allocation failure or the hwState allocation failure path. Add the missing check, use SynapticsHwStateFree() for symmetry with DeviceClose()'s normal-path cleanup, and NULL out open_slots after freeing it. Signed-off-by: Enrico Weigelt, metux IT consult <info@metux.net>
Contributor
Author
|
Note: could not locally build-verify this change — |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DeviceInit() checked priv->hwState and priv->local_hw_state for
allocation failure but not the third SynapticsHwStateAlloc() call
(priv->comm.hwState) -- SynapticsReset(), called right after, derefs
it unconditionally.
Separately, the 'fail' cleanup path used raw free() on hwState/
local_hw_state instead of SynapticsHwStateFree() (leaking their
nested slot_state/mt_mask allocations), and freed priv->open_slots
without resetting it to NULL. priv survives a failed DeviceInit() and
SynapticsUnInit() later frees priv->open_slots again if it's
still non-NULL, so this was a double-free on the open_slots
allocation failure or the hwState allocation failure path.
Add the missing check, use SynapticsHwStateFree() for symmetry with
DeviceClose()'s normal-path cleanup, and NULL out open_slots after
freeing it.
Signed-off-by: Enrico Weigelt, metux IT consult info@metux.net