Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1757754AbXFFFQM (ORCPT ); Wed, 6 Jun 2007 01:16:12 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1756170AbXFFFP6 (ORCPT ); Wed, 6 Jun 2007 01:15:58 -0400 Received: from netops-testserver-4-out.sgi.com ([192.48.171.29]:32851 "EHLO relay.sgi.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752051AbXFFFP6 (ORCPT ); Wed, 6 Jun 2007 01:15:58 -0400 Date: Tue, 5 Jun 2007 22:15:57 -0700 (PDT) From: Christoph Lameter X-X-Sender: clameter@schroedinger.engr.sgi.com To: young dave cc: Andrew Morton , Linux Kernel Mailing List Subject: Re: [BUG] 2.6.22-rc3-mm1 remove bluetooth usb adapter caused kmalloc bug In-Reply-To: Message-ID: References: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 477 Lines: 10 Note that the corruption seems to have its cause in a decrement done at offset 16 into the object pointing to the refcount in struct hci_dev. So it looks like the refcount was decremented after the object was freed. sysfs related? - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/