Commit 4a888aa9 authored by Richard Genoud's avatar Richard Genoud Committed by Ben Hutchings

mtd: nandsim: bugfix: fail if overridesize is too big

commit bb0a13a1 upstream.

If override size is too big, the module was actually loaded instead of
failing, because retval was not set.

This lead to memory corruption with the use of the freed structs nandsim
and nand_chip.
Signed-off-by: default avatarRichard Genoud <richard.genoud@gmail.com>
Signed-off-by: default avatarArtem Bityutskiy <artem.bityutskiy@linux.intel.com>
Signed-off-by: default avatarDavid Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: default avatarBen Hutchings <ben@decadent.org.uk>
parent f4c8c2f0
...@@ -2355,6 +2355,7 @@ static int __init ns_init_module(void) ...@@ -2355,6 +2355,7 @@ static int __init ns_init_module(void)
uint64_t new_size = (uint64_t)nsmtd->erasesize << overridesize; uint64_t new_size = (uint64_t)nsmtd->erasesize << overridesize;
if (new_size >> overridesize != nsmtd->erasesize) { if (new_size >> overridesize != nsmtd->erasesize) {
NS_ERR("overridesize is too big\n"); NS_ERR("overridesize is too big\n");
retval = -EINVAL;
goto err_exit; goto err_exit;
} }
/* N.B. This relies on nand_scan not doing anything with the size before we change it */ /* N.B. This relies on nand_scan not doing anything with the size before we change it */
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment