提交 c0181d42 编写于 作者: J Jarek Poplawski 提交者: David S. Miller

ax25: Fix ax25_cb refcounting in ax25_ctl_ioctl

Use ax25_cb_put after ax25_find_cb in ax25_ctl_ioctl.
Reported-by: NBernard Pidoux F6BVP <f6bvp@free.fr>
Signed-off-by: NJarek Poplawski <jarkao2@gmail.com>
Reviewed-by: NRalf Baechle <ralf@linux-mips.org>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 a91eba5b
...@@ -358,6 +358,7 @@ static int ax25_ctl_ioctl(const unsigned int cmd, void __user *arg) ...@@ -358,6 +358,7 @@ static int ax25_ctl_ioctl(const unsigned int cmd, void __user *arg)
ax25_dev *ax25_dev; ax25_dev *ax25_dev;
ax25_cb *ax25; ax25_cb *ax25;
unsigned int k; unsigned int k;
int ret = 0;
if (copy_from_user(&ax25_ctl, arg, sizeof(ax25_ctl))) if (copy_from_user(&ax25_ctl, arg, sizeof(ax25_ctl)))
return -EFAULT; return -EFAULT;
...@@ -388,57 +389,63 @@ static int ax25_ctl_ioctl(const unsigned int cmd, void __user *arg) ...@@ -388,57 +389,63 @@ static int ax25_ctl_ioctl(const unsigned int cmd, void __user *arg)
case AX25_WINDOW: case AX25_WINDOW:
if (ax25->modulus == AX25_MODULUS) { if (ax25->modulus == AX25_MODULUS) {
if (ax25_ctl.arg < 1 || ax25_ctl.arg > 7) if (ax25_ctl.arg < 1 || ax25_ctl.arg > 7)
return -EINVAL; goto einval_put;
} else { } else {
if (ax25_ctl.arg < 1 || ax25_ctl.arg > 63) if (ax25_ctl.arg < 1 || ax25_ctl.arg > 63)
return -EINVAL; goto einval_put;
} }
ax25->window = ax25_ctl.arg; ax25->window = ax25_ctl.arg;
break; break;
case AX25_T1: case AX25_T1:
if (ax25_ctl.arg < 1) if (ax25_ctl.arg < 1)
return -EINVAL; goto einval_put;
ax25->rtt = (ax25_ctl.arg * HZ) / 2; ax25->rtt = (ax25_ctl.arg * HZ) / 2;
ax25->t1 = ax25_ctl.arg * HZ; ax25->t1 = ax25_ctl.arg * HZ;
break; break;
case AX25_T2: case AX25_T2:
if (ax25_ctl.arg < 1) if (ax25_ctl.arg < 1)
return -EINVAL; goto einval_put;
ax25->t2 = ax25_ctl.arg * HZ; ax25->t2 = ax25_ctl.arg * HZ;
break; break;
case AX25_N2: case AX25_N2:
if (ax25_ctl.arg < 1 || ax25_ctl.arg > 31) if (ax25_ctl.arg < 1 || ax25_ctl.arg > 31)
return -EINVAL; goto einval_put;
ax25->n2count = 0; ax25->n2count = 0;
ax25->n2 = ax25_ctl.arg; ax25->n2 = ax25_ctl.arg;
break; break;
case AX25_T3: case AX25_T3:
if (ax25_ctl.arg < 0) if (ax25_ctl.arg < 0)
return -EINVAL; goto einval_put;
ax25->t3 = ax25_ctl.arg * HZ; ax25->t3 = ax25_ctl.arg * HZ;
break; break;
case AX25_IDLE: case AX25_IDLE:
if (ax25_ctl.arg < 0) if (ax25_ctl.arg < 0)
return -EINVAL; goto einval_put;
ax25->idle = ax25_ctl.arg * 60 * HZ; ax25->idle = ax25_ctl.arg * 60 * HZ;
break; break;
case AX25_PACLEN: case AX25_PACLEN:
if (ax25_ctl.arg < 16 || ax25_ctl.arg > 65535) if (ax25_ctl.arg < 16 || ax25_ctl.arg > 65535)
return -EINVAL; goto einval_put;
ax25->paclen = ax25_ctl.arg; ax25->paclen = ax25_ctl.arg;
break; break;
default: default:
return -EINVAL; goto einval_put;
} }
return 0; out_put:
ax25_cb_put(ax25);
return ret;
einval_put:
ret = -EINVAL;
goto out_put;
} }
static void ax25_fillin_cb_from_dev(ax25_cb *ax25, ax25_dev *ax25_dev) static void ax25_fillin_cb_from_dev(ax25_cb *ax25, ax25_dev *ax25_dev)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册