Skip to content
Snippets Groups Projects
user avatar
Eric Auger authored
In case the new region gets merged into another one, the nr list node is
freed.  Checking its type while completing the merge algorithm leads to
a use-after-free.  Use new->type instead.

Fixes: 4dbd258f ("iommu: Revisit iommu_insert_resv_region() implementation")
Signed-off-by: default avatarEric Auger <eric.auger@redhat.com>
Reported-by: default avatarQian Cai <cai@lca.pw>
Reviewed-by: default avatarJerry Snitselaar <jsnitsel@redhat.com>
Cc: Stable <stable@vger.kernel.org> #v5.3+
Signed-off-by: default avatarLinus Torvalds <torvalds@linux-foundation.org>
4c80ba39
History
Name Last commit Last update