[merged mm-nonmm-stable] rapidio-clear-mport-net-when-rio_add_net-fails.patch removed from -mm tree
Andrew Morton <[email protected]> Mon, 03 Aug 2026 21:05:21 -0700
| Newsgroups | org.kernel.vger.mm-commits |
|---|---|
| Message-ID | <[email protected]> |
The quilt patch titled
Subject: rapidio: clear mport->net when rio_add_net() fails
has been removed from the -mm tree. Its filename was
rapidio-clear-mport-net-when-rio_add_net-fails.patch
This patch was dropped because it was merged into the mm-nonmm-stable branch
of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
------------------------------------------------------
From: Guangshuo Li <[email protected]>
Subject: rapidio: clear mport->net when rio_add_net() fails
Date: Wed, 8 Jul 2026 15:06:28 +0800
rio_alloc_net() stores the newly allocated rio_net in mport->net before
rio_scan_alloc_net() registers the device.
If rio_add_net() fails, rio_scan_alloc_net() drops the device reference
with put_device(), which releases the rio_net through the device release
callback. However, mport->net is left pointing at the freed object.
A later mport unregister path can then dereference the dangling mport->net
pointer and may try to free the same rio_net again.
Clear mport->net in the rio_add_net() failure path, matching the cleanup
done for the destID table allocation failure path.
Link: https://lore.kernel.org/[email protected]
Fixes: e842f9a1edf3 ("rapidio: add check for rio_add_net() in rio_scan_alloc_net()")
Signed-off-by: Guangshuo Li <[email protected]>
Cc: Alexandre Bounine <[email protected]>
Cc: Matt Porter <[email protected]>
Cc: Yang yingliang <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---
drivers/rapidio/rio-scan.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/rapidio/rio-scan.c~rapidio-clear-mport-net-when-rio_add_net-fails
+++ a/drivers/rapidio/rio-scan.c
@@ -874,6 +874,7 @@ static struct rio_net *rio_scan_alloc_ne
net->dev.release = rio_scan_release_dev;
if (rio_add_net(net)) {
put_device(&net->dev);
+ mport->net = NULL;
net = NULL;
}
}
_
Patches currently in -mm which might be from [email protected] are