Files
i2som-imx-linux/drivers
Mikulas Patocka e41f30294b dm snapshot: fix a possible invalid memory access on unload
commit 22aa66a3ee upstream.

When the snapshot target is unloaded, snapshot_dtr() waits until
pending_exceptions_count drops to zero.  Then, it destroys the snapshot.
Therefore, the function that decrements pending_exceptions_count
should not touch the snapshot structure after the decrement.

pending_complete() calls free_pending_exception(), which decrements
pending_exceptions_count, and then it performs up_write(&s->lock) and it
calls retry_origin_bios() which dereferences  s->origin.  These two
memory accesses to the fields of the snapshot may touch the dm_snapshot
struture after it is freed.

This patch moves the call to free_pending_exception() to the end of
pending_complete(), so that the snapshot will not be destroyed while
pending_complete() is in progress.

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
2015-05-09 23:16:18 +01:00
..
2015-05-09 23:16:18 +01:00
2014-04-30 16:23:18 +01:00
2015-02-20 00:49:24 +00:00
2015-02-20 00:49:41 +00:00
2015-05-09 23:16:18 +01:00
2015-02-20 00:49:33 +00:00
2015-02-20 00:49:33 +00:00