diff options
author | Thomas Tai <thomas.tai@oracle.com> | 2018-07-26 13:13:04 -0400 |
---|---|---|
committer | Bjorn Helgaas <helgaas@kernel.org> | 2018-07-26 13:13:04 -0400 |
commit | bd91b56cb3b27492963caeb5fccefe20a986ca8d (patch) | |
tree | 3df6c7e55a6802db5af2b11791b52f120ed2ea5f | |
parent | 270ed733e68955049b693bea8f4a1efb293a96ae (diff) |
PCI/AER: Work around use-after-free in pcie_do_fatal_recovery()
When an fatal error is received by a non-bridge device, the device is
removed, and pci_stop_and_remove_bus_device() deallocates the device
structure. The freed device structure is used by subsequent code to send
uevents and print messages.
Hold a reference on the device until we're finished using it. This is not
an ideal fix because pcie_do_fatal_recovery() should not use the device at
all after removing it, but that's too big a project for right now.
Fixes: 7e9084b36740 ("PCI/AER: Handle ERR_FATAL with removal and re-enumeration of devices")
Signed-off-by: Thomas Tai <thomas.tai@oracle.com>
[bhelgaas: changelog, reduce get/put coverage]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
-rw-r--r-- | drivers/pci/pcie/err.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/drivers/pci/pcie/err.c b/drivers/pci/pcie/err.c index f7ce0cb0b0b7..f02e334beb45 100644 --- a/drivers/pci/pcie/err.c +++ b/drivers/pci/pcie/err.c | |||
@@ -295,6 +295,7 @@ void pcie_do_fatal_recovery(struct pci_dev *dev, u32 service) | |||
295 | 295 | ||
296 | parent = udev->subordinate; | 296 | parent = udev->subordinate; |
297 | pci_lock_rescan_remove(); | 297 | pci_lock_rescan_remove(); |
298 | pci_dev_get(dev); | ||
298 | list_for_each_entry_safe_reverse(pdev, temp, &parent->devices, | 299 | list_for_each_entry_safe_reverse(pdev, temp, &parent->devices, |
299 | bus_list) { | 300 | bus_list) { |
300 | pci_dev_get(pdev); | 301 | pci_dev_get(pdev); |
@@ -328,6 +329,7 @@ void pcie_do_fatal_recovery(struct pci_dev *dev, u32 service) | |||
328 | pci_info(dev, "Device recovery from fatal error failed\n"); | 329 | pci_info(dev, "Device recovery from fatal error failed\n"); |
329 | } | 330 | } |
330 | 331 | ||
332 | pci_dev_put(dev); | ||
331 | pci_unlock_rescan_remove(); | 333 | pci_unlock_rescan_remove(); |
332 | } | 334 | } |
333 | 335 | ||