dpaa_mbuf_free_pool() freed the pool private data and then wrote to it:

        rte_free(mp->pool_data);
        bp_info->bp = NULL;

bp_info is DPAA_MEMPOOL_TO_POOL_INFO(mp), which is mp->pool_data, so
both refer to the same allocation. Clearing bp_info->bp after the
rte_free() writes into freed memory.

Clear the field before releasing the allocation, and free bp_info
directly rather than the alias.

Fixes: 376fb49ecfca ("net/dpaa: prevent multiple mempool config")
Cc: [email protected]

Signed-off-by: Hemant Agrawal <[email protected]>
---
 drivers/mempool/dpaa/dpaa_mempool.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/mempool/dpaa/dpaa_mempool.c 
b/drivers/mempool/dpaa/dpaa_mempool.c
index 2f8555a026..94aea5e77c 100644
--- a/drivers/mempool/dpaa/dpaa_mempool.c
+++ b/drivers/mempool/dpaa/dpaa_mempool.c
@@ -143,8 +143,8 @@ dpaa_mbuf_free_pool(struct rte_mempool *mp)
                bman_free_pool(bp_info->bp);
                DPAA_MEMPOOL_INFO("BMAN pool freed for bpid =%d",
                                  bp_info->bpid);
-               rte_free(mp->pool_data);
                bp_info->bp = NULL;
+               rte_free(bp_info);
                mp->pool_data = NULL;
        }
 }
-- 
2.25.1

Reply via email to