[PATCH 7.1 078/271] bnge: Fix NULL pointer dereference in aux device release

Greg Kroah-Hartman <[email protected]>
Newsgroups dev.linux.lists.patches,org.kernel.vger.stable
Message-ID <[email protected]>
7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alok Tiwari <[email protected]>

[ Upstream commit 1cb4298810e27e037d3ca07286ecbb97e89ba58d ]

If allocation of auxr_dev fails during auxiliary device setup, the error
path calls auxiliary_device_uninit(), which eventually invokes
bnge_aux_dev_release().

The release callback unconditionally dereferences aux_priv->auxr_dev->pdev
to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated
on this failure path, the dereference results in a NULL pointer exception

Retrieve the parent bnge_dev from the auxiliary device's parent instead of
auxr_dev, and free auxr_dev only when it was successfully allocated. This
allows the release callback to correctly clean up partially initialized
auxiliary devices.

Fixes: 8ac050ec3b1c ("bng_en: Add RoCE aux device support")
Signed-off-by: Alok Tiwari <[email protected]>
Reviewed-by: Bhargava Marreddy <[email protected]>
Link: https://patch.msgid.link/[email protected]
Signed-off-by: Jakub Kicinski <[email protected]>
Signed-off-by: Sasha Levin <[email protected]>
---
 drivers/net/ethernet/broadcom/bnge/bnge_auxr.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/broadcom/bnge/bnge_auxr.c b/drivers/net/ethernet/broadcom/bnge/bnge_auxr.c
index 67e93e17d4d9f..0955b488b6fea 100644
--- a/drivers/net/ethernet/broadcom/bnge/bnge_auxr.c
+++ b/drivers/net/ethernet/broadcom/bnge/bnge_auxr.c
@@ -141,12 +141,15 @@ static void bnge_aux_dev_release(struct device *dev)
 {
 	struct bnge_auxr_priv *aux_priv =
 			container_of(dev, struct bnge_auxr_priv, aux_dev.dev);
-	struct bnge_dev *bd = pci_get_drvdata(aux_priv->auxr_dev->pdev);
+	struct bnge_auxr_dev *auxr_dev = aux_priv->auxr_dev;
+	struct bnge_dev *bd = pci_get_drvdata(to_pci_dev(dev->parent));
 
 	ida_free(&bnge_aux_dev_ids, aux_priv->id);
-	kfree(aux_priv->auxr_dev->auxr_info);
+	if (auxr_dev) {
+		kfree(auxr_dev->auxr_info);
+		kfree(auxr_dev);
+	}
 	bd->auxr_dev = NULL;
-	kfree(aux_priv->auxr_dev);
 	kfree(aux_priv);
 	bd->aux_priv = NULL;
 }
-- 
2.53.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.