forked from rubenslte/android_kernel_samsung_msm8226
ion: invalidate the pool pointers after free
ion_system_heap_destroy_pools frees the pool, but does not invalidate the pointer. This can result in a double free if ion_system_heap_create_pools fails, and then causes ion_system_heap_create to call into ion_system_heap_destroy_pools again from the error path. This can happen in ion_system_heap_create when one of the secure pool creation fails. Change-Id: Ic73ca78722aa5a575cc4dd7c1caa560b518094f2 Signed-off-by: Vinayak Menon <vinmenon@codeaurora.org> [haggertk: Backport to 3.4/msm8974] CVE-2018-11987 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
ae53ad4ca7
commit
6a14021cd6
@@ -455,8 +455,10 @@ static void ion_system_heap_destroy_pools(struct ion_page_pool **pools)
|
||||
{
|
||||
int i;
|
||||
for (i = 0; i < num_orders; i++)
|
||||
if (pools[i])
|
||||
if (pools[i]) {
|
||||
ion_page_pool_destroy(pools[i]);
|
||||
pools[i] = NULL;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user