Input: atmel_mxt_ts - fix double free in mxt_read_info_block
commit12f247ab59
upstream. The "id_buf" buffer is stored in "data->raw_info_block" and freed by "mxt_free_object_table" in case of error. Return instead of jumping to avoid a double free. Addresses-Coverity-ID: 1474582 ("Double free") Fixes:068bdb67ef
("Input: atmel_mxt_ts - fix the firmware update") Signed-off-by: José Expósito <jose.exposito89@gmail.com> Link: https://lore.kernel.org/r/20211212194257.68879-1-jose.exposito89@gmail.com Cc: stable@vger.kernel.org Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Родитель
6084a6c1ca
Коммит
7f7f61042f
|
@ -1882,7 +1882,7 @@ static int mxt_read_info_block(struct mxt_data *data)
|
||||||
if (error) {
|
if (error) {
|
||||||
dev_err(&client->dev, "Error %d parsing object table\n", error);
|
dev_err(&client->dev, "Error %d parsing object table\n", error);
|
||||||
mxt_free_object_table(data);
|
mxt_free_object_table(data);
|
||||||
goto err_free_mem;
|
return error;
|
||||||
}
|
}
|
||||||
|
|
||||||
data->object_table = (struct mxt_object *)(id_buf + MXT_OBJECT_START);
|
data->object_table = (struct mxt_object *)(id_buf + MXT_OBJECT_START);
|
||||||
|
|
Загрузка…
Ссылка в новой задаче