mirror of
https://github.com/SCST-project/scst.git
synced 2026-08-18 13:16:34 +00:00
qla2x00t-32gbit: Fix use after free in debug code
The sp->free(sp); call frees "sp" and then the debug code dereferences it on the next line. Swap the order. Link: https://lore.kernel.org/r/20210803155625.GA22735@kili Fixes: 84318a9f01ce ("scsi: qla2xxx: edif: Add send, receive, and accept for auth_els") Reviewed-by: Ewan D. Milne <emilne@redhat.com> Reviewed-by: Himanshu Madhani <himanshu.madhani@oracle.com> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com> [ commit e3d2612f583ba6e234cb7fe4559132c8f28905f1 upstream ] git-svn-id: http://svn.code.sf.net/p/scst/svn/trunk@9538 d57e44dd-8a1f-0410-8b47-8ef2f437770f
This commit is contained in:
@@ -46,12 +46,12 @@ void qla2x00_bsg_job_done(srb_t *sp, int res)
|
||||
BSG_JOB_TYPE *bsg_job = sp->u.bsg_job;
|
||||
struct fc_bsg_reply *bsg_reply = bsg_job->reply;
|
||||
|
||||
sp->free(sp);
|
||||
|
||||
ql_dbg(ql_dbg_user, sp->vha, 0x7009,
|
||||
"%s: sp hdl %x, result=%x bsg ptr %p\n",
|
||||
__func__, sp->handle, res, bsg_job);
|
||||
|
||||
sp->free(sp);
|
||||
|
||||
bsg_reply->result = res;
|
||||
bsg_job_done(bsg_job, bsg_reply->result,
|
||||
bsg_reply->reply_payload_rcv_len);
|
||||
|
||||
Reference in New Issue
Block a user