mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-29 01:04:14 -04:00
bnge: Fix NULL pointer dereference in aux device release
If allocation of auxr_dev fails during auxiliary device setup, the error
path calls auxiliary_device_uninit(), which eventually invokes
bnge_aux_dev_release().
The release callback unconditionally dereferences aux_priv->auxr_dev->pdev
to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated
on this failure path, the dereference results in a NULL pointer exception
Retrieve the parent bnge_dev from the auxiliary device's parent instead of
auxr_dev, and free auxr_dev only when it was successfully allocated. This
allows the release callback to correctly clean up partially initialized
auxiliary devices.
Fixes: 8ac050ec3b ("bng_en: Add RoCE aux device support")
Signed-off-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Reviewed-by: Bhargava Marreddy <bhargava.marreddy@broadcom.com>
Link: https://patch.msgid.link/20260731192301.1427645-1-alok.a.tiwari@oracle.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
committed by
Jakub Kicinski
parent
1f428e3094
commit
1cb4298810
@@ -141,12 +141,15 @@ static void bnge_aux_dev_release(struct device *dev)
|
||||
{
|
||||
struct bnge_auxr_priv *aux_priv =
|
||||
container_of(dev, struct bnge_auxr_priv, aux_dev.dev);
|
||||
struct bnge_dev *bd = pci_get_drvdata(aux_priv->auxr_dev->pdev);
|
||||
struct bnge_auxr_dev *auxr_dev = aux_priv->auxr_dev;
|
||||
struct bnge_dev *bd = pci_get_drvdata(to_pci_dev(dev->parent));
|
||||
|
||||
ida_free(&bnge_aux_dev_ids, aux_priv->id);
|
||||
kfree(aux_priv->auxr_dev->auxr_info);
|
||||
if (auxr_dev) {
|
||||
kfree(auxr_dev->auxr_info);
|
||||
kfree(auxr_dev);
|
||||
}
|
||||
bd->auxr_dev = NULL;
|
||||
kfree(aux_priv->auxr_dev);
|
||||
kfree(aux_priv);
|
||||
bd->aux_priv = NULL;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user