bnxt: add a missing rcu synchronization
authorEric Dumazet <edumazet@google.com>
Wed, 16 Nov 2016 14:31:52 +0000 (06:31 -0800)
committerDavid S. Miller <davem@davemloft.net>
Thu, 17 Nov 2016 04:30:43 +0000 (23:30 -0500)
Add a missing synchronize_net() call to avoid potential use after free,
since we explicitly call napi_hash_del() to factorize the RCU grace
period.

Fixes: c0c050c58d84 ("bnxt_en: New Broadcom ethernet driver.")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Michael Chan <michael.chan@broadcom.com>
Acked-by: Michael Chan <michael.chan@broadcom.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
drivers/net/ethernet/broadcom/bnxt/bnxt.c

index c6909660e097b010fe30c3371fefa253fd71e5d5..e18635b2a002d505be7bf330793f364b49c2eb0d 100644 (file)
@@ -4934,6 +4934,10 @@ static void bnxt_del_napi(struct bnxt *bp)
                napi_hash_del(&bnapi->napi);
                netif_napi_del(&bnapi->napi);
        }
+       /* We called napi_hash_del() before netif_napi_del(), we need
+        * to respect an RCU grace period before freeing napi structures.
+        */
+       synchronize_net();
 }
 
 static void bnxt_init_napi(struct bnxt *bp)