summaryrefslogtreecommitdiffstats
path: root/drivers/isdn/gigaset
diff options
context:
space:
mode:
authorDan Carpenter <error27@gmail.com>2010-08-06 00:21:26 +0200
committerDavid S. Miller <davem@davemloft.net>2010-08-08 08:04:12 +0200
commit8bcfbd0af0f8ee50033091e75ab3d6b6e7fa8867 (patch)
tree10b10edd8ecc8020e7ae2182ddf7fa06761523c6 /drivers/isdn/gigaset
parentisdn: gigaset: add missing unlock (diff)
downloadlinux-8bcfbd0af0f8ee50033091e75ab3d6b6e7fa8867.tar.xz
linux-8bcfbd0af0f8ee50033091e75ab3d6b6e7fa8867.zip
isdn: gigaset: use after free
I moved the kfree(cb) below the dereferences. Signed-off-by: Dan Carpenter <error27@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'drivers/isdn/gigaset')
-rw-r--r--drivers/isdn/gigaset/bas-gigaset.c6
1 files changed, 4 insertions, 2 deletions
diff --git a/drivers/isdn/gigaset/bas-gigaset.c b/drivers/isdn/gigaset/bas-gigaset.c
index 0ded3640b926..707d9c94cf9e 100644
--- a/drivers/isdn/gigaset/bas-gigaset.c
+++ b/drivers/isdn/gigaset/bas-gigaset.c
@@ -1914,11 +1914,13 @@ static int gigaset_write_cmd(struct cardstate *cs, struct cmdbuf_t *cb)
* The next command will reopen the AT channel automatically.
*/
if (cb->len == 3 && !memcmp(cb->buf, "+++", 3)) {
- kfree(cb);
rc = req_submit(cs->bcs, HD_CLOSE_ATCHANNEL, 0, BAS_TIMEOUT);
if (cb->wake_tasklet)
tasklet_schedule(cb->wake_tasklet);
- return rc < 0 ? rc : cb->len;
+ if (!rc)
+ rc = cb->len;
+ kfree(cb);
+ return rc;
}
spin_lock_irqsave(&cs->cmdlock, flags);