When register_virtio_device() fails in virtio_uml_probe(),
the code sets vu_dev->registered = 1 even though
the device was not successfully registered.
This can lead to use-after-free or other issues.

Fixes: 04e5b1fb0183 ("um: virtio: Remove device on disconnect")
Signed-off-by: Miaoqian Lin <[email protected]>
---
changes in v2:
- statically 'return 0' in the normal path.
- v1 link: 
https://lore.kernel.org/all/[email protected]/
---
 arch/um/drivers/virtio_uml.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/arch/um/drivers/virtio_uml.c b/arch/um/drivers/virtio_uml.c
index ad8d78fb1d9a..de7867ae220d 100644
--- a/arch/um/drivers/virtio_uml.c
+++ b/arch/um/drivers/virtio_uml.c
@@ -1250,10 +1250,12 @@ static int virtio_uml_probe(struct platform_device 
*pdev)
        device_set_wakeup_capable(&vu_dev->vdev.dev, true);
 
        rc = register_virtio_device(&vu_dev->vdev);
-       if (rc)
+       if (rc) {
                put_device(&vu_dev->vdev.dev);
+               return rc;
+       }
        vu_dev->registered = 1;
-       return rc;
+       return 0;
 
 error_init:
        os_close_file(vu_dev->sock);
-- 
2.39.5 (Apple Git-154)


Reply via email to