Unverified Commit ff3881cc authored by Dan Carpenter's avatar Dan Carpenter Committed by Maxime Ripard
Browse files

drm: writeback: Fix use after free in drm_writeback_connector_cleanup()



The drm_writeback_cleanup_job() function frees "pos" so call
list_del(&pos->list_entry) first to avoid a use after free.

Fixes: 1914ba2b ("drm: writeback: Create drmm variants for drm_writeback_connector initialization")
Signed-off-by: default avatarDan Carpenter <dan.carpenter@linaro.org>
Reviewed-by: default avatarDmitry Baryshkov <dmitry.baryshkov@linaro.org>
Link: https://patchwork.freedesktop.org/patch/msgid/78abd541-71e9-4b3b-a05d-2c7caf8d5b2f@stanley.mountain


Signed-off-by: default avatarMaxime Ripard <mripard@kernel.org>
parent e5f5f7cc
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -360,8 +360,8 @@ static void drm_writeback_connector_cleanup(struct drm_device *dev,

	spin_lock_irqsave(&wb_connector->job_lock, flags);
	list_for_each_entry_safe(pos, n, &wb_connector->job_queue, list_entry) {
		drm_writeback_cleanup_job(pos);
		list_del(&pos->list_entry);
		drm_writeback_cleanup_job(pos);
	}
	spin_unlock_irqrestore(&wb_connector->job_lock, flags);
}