diff options
| author | Roland Dreier <rolandd@cisco.com> | 2008-06-10 15:29:49 -0400 | 
|---|---|---|
| committer | Roland Dreier <rolandd@cisco.com> | 2008-06-10 15:29:49 -0400 | 
| commit | 24797a344293601f14f49e2d259c3ca447c4f802 (patch) | |
| tree | cab0bcd13e61696ddda726ded59bd5428f72bd56 /mm/backing-dev.c | |
| parent | 5e70b7f3c24468bb1635b295945edb48ecd9656a (diff) | |
RDMA/nes: Fix off-by-one in nes_reg_user_mr() error path
nes_reg_user_mr() should fail if page_count becomes >= 1024 * 512
rather than just testing for strict >, because page_count is
essentially used as an index into an array with 1024 * 512 entries, so
allowing the loop to continue with page_count == 1024 * 512 means that
memory after the end of the array is corrupted.  This leads to a crash
triggerable by a userspace application that requests registration of a
too-big region.
Also get rid of the call to pci_free_consistent() here to avoid
corrupting state with a double free, since the same memory will be
freed in the code jumped to at reg_user_mr_err.
Signed-off-by: Roland Dreier <rolandd@cisco.com>
Diffstat (limited to 'mm/backing-dev.c')
0 files changed, 0 insertions, 0 deletions
