From: David Woodhouse Date: Tue, 11 Dec 2012 14:57:14 +0000 (+0000) Subject: solos-pci: fix double-free of TX skb in DMA mode X-Git-Tag: v5.15~21098^2~8 X-Git-Url: https://git.proxmox.com/?a=commitdiff_plain;h=cae49ede00ec3d0cda290b03fee55b72b49efc11;p=mirror_ubuntu-kernels.git solos-pci: fix double-free of TX skb in DMA mode We weren't clearing card->tx_skb[port] when processing the TX done interrupt. If there wasn't another skb ready to transmit immediately, this led to a double-free because we'd free it *again* next time we did have a packet to send. Signed-off-by: David Woodhouse Cc: stable@kernel.org Signed-off-by: David S. Miller --- diff --git a/drivers/atm/solos-pci.c b/drivers/atm/solos-pci.c index 6619a8a9607c..c909b7b7d5f1 100644 --- a/drivers/atm/solos-pci.c +++ b/drivers/atm/solos-pci.c @@ -945,10 +945,11 @@ static uint32_t fpga_tx(struct solos_card *card) for (port = 0; tx_pending; tx_pending >>= 1, port++) { if (tx_pending & 1) { struct sk_buff *oldskb = card->tx_skb[port]; - if (oldskb) + if (oldskb) { pci_unmap_single(card->dev, SKB_CB(oldskb)->dma_addr, oldskb->len, PCI_DMA_TODEVICE); - + card->tx_skb[port] = NULL; + } spin_lock(&card->tx_queue_lock); skb = skb_dequeue(&card->tx_queue[port]); if (!skb)