DragonFlyBSD Kernel Audit
← triage · dashboard
DF-2573

NULL deref / panic: SLIST_REMOVE on connection never inserted in error paths of ng_device_newhook

Summary

Both error paths in ng_device_newhook call SLIST_REMOVE on new_connection but SLIST_INSERT_HEAD does not happen until :309 well after these error branches. SLIST_REMOVE on not-inserted element walks off end of list dereferences NULL panicking kernel whenever make_dev or readq kmalloc fails under memory pressure. SLIST_REMOVE enters else branch curelm=SLIST_FIRST(head) if list empty curelm NULL SLIST_NEXT dereferences NULL.

Discussion (0)

No comments yet.