When an SG URB completes with an error, mts_do_sg() calls
mts_transfer_cleanup(), which completes the SCSI command through
scsi_done(). However, the callback continues advancing the scatterlist
and may submit another URB for a command that has already been
completed.
Return immediately after the cleanup so that no further processing is
performed on the completed command.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Diego Fernando Mancera Gomez <diegomancera.dev@gmail.com>
---
drivers/usb/image/microtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/usb/image/microtek.c b/drivers/usb/image/microtek.c
index 1f0b3c44d388..787cf5aba55d 100644
--- a/drivers/usb/image/microtek.c
+++ b/drivers/usb/image/microtek.c
@@ -475,6 +475,7 @@ static void mts_do_sg (struct urb* transfer)
if (unlikely(status)) {
set_host_byte(context->srb, (status == -ENOENT ? DID_ABORT : DID_ERROR));
mts_transfer_cleanup(transfer);
+ return;
}
context->curr_sg = sg_next(context->curr_sg);
--
2.43.0