Re: [PATCH v3] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()

Frank Li <[email protected]>
Newsgroups org.kernel.vger.dmaengine,org.kernel.vger.linux-kernel
Message-ID <aoYHK2vV8B49ETVY@lizhi-Precision-Tower-5810>
On Wed, Aug 12, 2026 at 08:34:26AM +0300, [email protected] wrote:
> From: Alexander Chesnokov <[email protected]>
>
> If devm_kcalloc() for rx_chn->flows fails in a channel request function,
> the error path calls k3_udma_glue_release_rx_chn(), which dereferences
> the NULL rx_chn->flows pointer in k3_udma_glue_release_rx_flow().
>
> Skip the flow release loop in k3_udma_glue_release_rx_chn() when
> rx_chn->flows is not allocated.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: d70241913413 ("dmaengine: ti: k3-udma: Add glue layer for non DMAengine users")
> Cc: [email protected]
> Reported-by: Pavel Zhigulin <[email protected]>
> Signed-off-by: Alexander Chesnokov <[email protected]>
> ---

Reviewed-by: Frank Li <[email protected]>

>
> v3: guard the flow release loop in k3_udma_glue_release_rx_chn() instead
> of reordering the flow_num assignment. Covers all error paths in both
> request functions.
> v2: https://lore.kernel.org/all/[email protected]/
>
>  drivers/dma/ti/k3-udma-glue.c | 5 +++--
>  1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/dma/ti/k3-udma-glue.c b/drivers/dma/ti/k3-udma-glue.c
> index 4f1aeb81e9c7..a739e60b0764 100644
> --- a/drivers/dma/ti/k3-udma-glue.c
> +++ b/drivers/dma/ti/k3-udma-glue.c
> @@ -1103,8 +1103,9 @@ void k3_udma_glue_release_rx_chn(struct k3_udma_glue_rx_channel *rx_chn)
>  		rx_chn->psil_paired = false;
>  	}
>
> -	for (i = 0; i < rx_chn->flow_num; i++)
> -		k3_udma_glue_release_rx_flow(rx_chn, i);
> +	if (rx_chn->flows)
> +		for (i = 0; i < rx_chn->flow_num; i++)
> +			k3_udma_glue_release_rx_flow(rx_chn, i);
>
>  	if (xudma_rflow_is_gp(rx_chn->common.udmax, rx_chn->flow_id_base))
>  		xudma_free_gp_rflow_range(rx_chn->common.udmax,
> --
> 2.43.0
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.