]> git.hungrycats.org Git - linux/commitdiff
[PATCH] Fix potential leaks in pc300_tty driver
authorDave Jones <davej@redhat.com>
Thu, 2 Sep 2004 07:38:17 +0000 (00:38 -0700)
committerLinus Torvalds <torvalds@ppc970.osdl.org>
Thu, 2 Sep 2004 07:38:17 +0000 (00:38 -0700)
It appears that 'new' can be allocated, and next time around
the loop, if something goes wrong, we lose the reference..

Spotted with the source checker from Coverity.com.

Signed-off-by: Dave Jones <davej@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
drivers/net/wan/pc300_tty.c

index 79d6894acd1f54f6ca6faec4adbc96c29ef9c97a..b8f4c78abf83b1ac593f2560b4a69d628818c54a 100644 (file)
@@ -789,6 +789,10 @@ void cpc_tty_receive(pc300dev_t *pc300dev)
                                cpc_writel(card->hw.scabase + DRX_REG(EDAL, ch), 
                                                RX_BD_ADDR(ch, pc300chan->rx_last_bd)); 
                        }
+                       if (new) {
+                               kfree(new);
+                               new = NULL;
+                       }
                        return; 
                }
                
@@ -834,7 +838,8 @@ void cpc_tty_receive(pc300dev_t *pc300dev)
                                                cpc_tty->name);
                                cpc_tty_rx_disc_frame(pc300chan);
                                rx_len = 0;
-                               kfree((unsigned char *)new);
+                               kfree(new);
+                               new = NULL;
                                break; /* read next frame - while(1) */
                        }
 
@@ -843,7 +848,8 @@ void cpc_tty_receive(pc300dev_t *pc300dev)
                                cpc_tty_rx_disc_frame(pc300chan);
                                stats->rx_dropped++; 
                                rx_len = 0; 
-                               kfree((unsigned char *)new);
+                               kfree(new);
+                               new = NULL;
                                break; /* read next frame - while(1) */
                        }