Call init_timer() for ISDN PPP CCP reset state timer (CVE-2006-5749)
The function isdn_ppp_ccp_reset_alloc_state() sets ->timer.function and ->timer.data and later on calls add_timer() with no init_timer() ever done. Noted by Al Viro. Signed-off-by: Marcel Holtmann <marcel@holtmann.org> Signed-off-by: Adrian Bunk <bunk@stusta.de>
This commit is contained in:
committed by
Adrian Bunk
parent
7c876d457b
commit
bb3e712f45
@@ -2346,6 +2346,7 @@ static struct ippp_ccp_reset_state *isdn_ppp_ccp_reset_alloc_state(struct ippp_s
|
||||
rs->state = CCPResetIdle;
|
||||
rs->is = is;
|
||||
rs->id = id;
|
||||
init_timer(&rs->timer);
|
||||
rs->timer.data = (unsigned long)rs;
|
||||
rs->timer.function = isdn_ppp_ccp_timer_callback;
|
||||
is->reset->rs[id] = rs;
|
||||
|
||||
Reference in New Issue
Block a user