Re: [PATCH RFC] firewire: ohci: fix NULL pointer dereference in ar_context_release

Aleksandr Nogikh <[email protected]>
Newsgroups dev.linux.lists.syzbot
Message-ID <CANp29Y7bgpsUue2Sja_x9Qc-yf9Er_1y2KtMuugbWVf6c8wYhA@mail.gmail.com>
#syz upstream


On Fri, Aug 7, 2026 at 12:09 PM 'syzbot' via
syzkaller-upstream-moderation
<[email protected]> wrote:
>
> During the error handling path of the driver's probe function, a NULL
> pointer dereference can occur in ar_context_release().
>
> When pci_probe() fails early (e.g., if pcim_enable_device() or MMIO mapping
> fails), the devres cleanup mechanism invokes release_ohci(). This function
> unconditionally calls ar_context_release() to clean up the asynchronous
> receive contexts. However, if ar_context_init() was not yet called,
> ctx->ohci remains NULL (as the fw_ohci structure is zero-initialized by
> devres_alloc()).
>
> ar_context_release() immediately dereferences ctx->ohci to get the dev
> pointer before checking if the context was actually initialized, leading to
> a crash:
>
> Oops: general protection fault, probably for non-canonical address
> 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI
> KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
> RIP: 0010:ar_context_release+0x3f/0x380 drivers/firewire/ohci.c:543
> Call Trace:
>  release_ohci+0x3f/0x60 drivers/firewire/ohci.c:3567
>  release_nodes drivers/base/devres.c:546 [inline]
>  devres_release_all+0x1a8/0x260 drivers/base/devres.c:576
>  device_unbind_cleanup drivers/base/dd.c:597 [inline]
>  really_probe+0x451/0xae0 drivers/base/dd.c:772
>
> To fix this, move the assignment of the dev pointer after the !ctx->buffer
> check. If ctx->buffer is NULL, it indicates that the context was never
> successfully initialized and there is nothing to release, safely avoiding
> the dereference of the uninitialized ctx->ohci pointer.
>
> Fixes: 5716e58aecdd ("firewire: ohci: release buffer for AR req/resp contexts when managed resource is released")
> Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=d30aad27833a559defab
> Link: https://syzkaller.appspot.com/ai_job?id=10a18617-7893-42dd-bf1c-cd49e19e95d9
> To: <[email protected]>
> To: "Takashi Sakamoto" <[email protected]>
> Cc: <[email protected]>
>
> ---
> diff --git a/drivers/firewire/ohci.c b/drivers/firewire/ohci.c
> index 8153d62c5..e947227e0 100644
> --- a/drivers/firewire/ohci.c
> +++ b/drivers/firewire/ohci.c
> @@ -540,11 +540,13 @@ static void ar_context_link_page(struct ar_context *ctx, unsigned int index)
>
>  static void ar_context_release(struct ar_context *ctx)
>  {
> -       struct device *dev = ctx->ohci->card.device;
> +       struct device *dev;
>
>         if (!ctx->buffer)
>                 return;
>
> +       dev = ctx->ohci->card.device;
> +
>         for (int i = 0; i < AR_BUFFERS; ++i) {
>                 dma_addr_t dma_addr = ctx->dma_addrs[i];
>                 if (dma_addr)
>
>
> base-commit: 075b74841bd0065a3bda3440873c747938e69b68
> --
> This is an AI-generated patch subject to moderation.
> Reply with '#syz upstream' to Sign-off the patch as a human author
> and send it to the upstream kernel mailing lists.
> Reply with '#syz reject' to reject it ('#syz unreject' to undo).
>
> See https://goo.gle/syzbot-ai-patches for information about AI-generated patches.
> The person who has signed off on the patch is responsible for
> addressing comments.
> syzbot engineers can be reached at [email protected].
>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-upstream-moderation" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
> To view this discussion visit https://groups.google.com/d/msgid/syzkaller-upstream-moderation/eb1357dd-f393-49f1-8e3d-60888cbb683c%40mail.kernel.org.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.