bnge: Fix NULL pointer dereference in aux device release

If allocation of auxr_dev fails during auxiliary device setup, the error
path calls auxiliary_device_uninit(), which eventually invokes
bnge_aux_dev_release().

The release callback unconditionally dereferences aux_priv->auxr_dev->pdev
to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated
on this failure path, the dereference results in a NULL pointer exception

Retrieve the parent bnge_dev from the auxiliary device's parent instead of
auxr_dev, and free auxr_dev only when it was successfully allocated. This
allows the release callback to correctly clean up partially initialized
auxiliary devices.

Fixes: 8ac050ec3b ("bng_en: Add RoCE aux device support")
Signed-off-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Reviewed-by: Bhargava Marreddy <bhargava.marreddy@broadcom.com>
Link: https://patch.msgid.link/20260731192301.1427645-1-alok.a.tiwari@oracle.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
Alok Tiwari
2026-07-31 12:22:59 -07:00
committed by Jakub Kicinski
parent 1f428e3094
commit 1cb4298810

View File

@@ -141,12 +141,15 @@ static void bnge_aux_dev_release(struct device *dev)
{
struct bnge_auxr_priv *aux_priv =
container_of(dev, struct bnge_auxr_priv, aux_dev.dev);
struct bnge_dev *bd = pci_get_drvdata(aux_priv->auxr_dev->pdev);
struct bnge_auxr_dev *auxr_dev = aux_priv->auxr_dev;
struct bnge_dev *bd = pci_get_drvdata(to_pci_dev(dev->parent));
ida_free(&bnge_aux_dev_ids, aux_priv->id);
kfree(aux_priv->auxr_dev->auxr_info);
if (auxr_dev) {
kfree(auxr_dev->auxr_info);
kfree(auxr_dev);
}
bd->auxr_dev = NULL;
kfree(aux_priv->auxr_dev);
kfree(aux_priv);
bd->aux_priv = NULL;
}