[PATCH] possible use-after-free of bio
authorJens Axboe <axboe@suse.de>
Sat, 16 Apr 2005 22:25:40 +0000 (15:25 -0700)
committerLinus Torvalds <torvalds@ppc970.osdl.org>
Sat, 16 Apr 2005 22:25:40 +0000 (15:25 -0700)
commit4a534f93b371e8e6e87ae302757365f0f583e06b
treef9ed5470c81bd63dba86f425a2c3731802000c79
parent9c340d80f66faaea3522812d0d8c91d6a1b48a22
[PATCH] possible use-after-free of bio

There is a possibility that a bio will be accessed after it has been freed
on SCSI.  It happens if you submit a bio with BIO_SYNC marked and the
auto-unplugging kicks the request_fn, SCSI re-enables interrupts in-between
so if the request completes between the add_request() in __make_request()
and the bio_sync() call, we could be looking at a dead bio.  It's a slim
race, but it has been triggered in the Real World.

So assign bio_sync() to a local variable instead.

Signed-off-by: Jens Axboe <axboe@suse.de>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
drivers/block/ll_rw_blk.c