RDMA/ocrdma: Fix use after free in ocrdma_dealloc_ucontext_pd()
authorTom Rix <trix@redhat.com>
Wed, 30 Dec 2020 02:46:53 +0000 (18:46 -0800)
committerJason Gunthorpe <jgg@nvidia.com>
Thu, 7 Jan 2021 20:37:11 +0000 (16:37 -0400)
commitf2bc3af6353cb2a33dfa9d270d999d839eef54cb
treec6f158c01dc4919e6957b40be489d3e5684456b9
parenta306aba9c8d869b1fdfc8ad9237f1ed718ea55e6
RDMA/ocrdma: Fix use after free in ocrdma_dealloc_ucontext_pd()

In ocrdma_dealloc_ucontext_pd() uctx->cntxt_pd is assigned to the variable
pd and then after uctx->cntxt_pd is freed, the variable pd is passed to
function _ocrdma_dealloc_pd() which dereferences pd directly or through
its call to ocrdma_mbx_dealloc_pd().

Reorder the free using the variable pd.

Cc: stable@vger.kernel.org
Fixes: 21a428a019c9 ("RDMA: Handle PD allocations by IB/core")
Link: https://lore.kernel.org/r/20201230024653.1516495-1-trix@redhat.com
Signed-off-by: Tom Rix <trix@redhat.com>
Reviewed-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
drivers/infiniband/hw/ocrdma/ocrdma_verbs.c