ion: invalidate the pool pointers after free

ion_system_heap_destroy_pools frees the pool, but
does not invalidate the pointer. This can result in
a double free if ion_system_heap_create_pools fails,
and then causes ion_system_heap_create to call into
ion_system_heap_destroy_pools again from the error
path. This can happen in ion_system_heap_create when
one of the secure pool creation fails.

Change-Id: Ic73ca78722aa5a575cc4dd7c1caa560b518094f2
Signed-off-by: Vinayak Menon <vinmenon@codeaurora.org>
[haggertk: Backport to 3.4/msm8974]
CVE-2018-11987
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
Vinayak Menon
2019-08-09 11:42:04 +02:00
committed by Francescodario Cuzzocrea
parent ae53ad4ca7
commit 6a14021cd6
+3 -1
View File
@@ -455,8 +455,10 @@ static void ion_system_heap_destroy_pools(struct ion_page_pool **pools)
{
int i;
for (i = 0; i < num_orders; i++)
if (pools[i])
if (pools[i]) {
ion_page_pool_destroy(pools[i]);
pools[i] = NULL;
}
}
/**