Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1405033 > unrolled thread
| Started by | Colin King <colin.king@canonical.com> |
|---|---|
| First post | 2016-05-22 21:10 +0200 |
| Last post | 2016-05-22 23:30 +0200 |
| Articles | 3 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH] net/ethoc: fix null dereference on error exit path Colin King <colin.king@canonical.com> - 2016-05-22 21:10 +0200
Re: [PATCH] net/ethoc: fix null dereference on error exit path Max Filippov <jcmvbkbc@gmail.com> - 2016-05-22 21:50 +0200
Re: [PATCH] net/ethoc: fix null dereference on error exit path Colin Ian King <colin.king@canonical.com> - 2016-05-22 23:30 +0200
| From | Colin King <colin.king@canonical.com> |
|---|---|
| Date | 2016-05-22 21:10 +0200 |
| Subject | [PATCH] net/ethoc: fix null dereference on error exit path |
| Message-ID | <rBGVc-4wz-15@gated-at.bofh.it> |
From: Colin Ian King <colin.king@canonical.com> priv is assigned to NULL however all the error exit paths to label 'free' dereference priv, causing a null pointer dereference. Examination of the code shows that all error exits via the 'free' label path occur before priv is assigned to netdev_priv(netdev), hence there is no need to call clk_disable_unprepare and so the location of the label should be moved to free_netdev statement to avoid this null dereference on priv. Fixes issue found by CoverityScan, CID#113260 Signed-off-by: Colin Ian King <colin.king@canonical.com> --- drivers/net/ethernet/ethoc.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/net/ethernet/ethoc.c b/drivers/net/ethernet/ethoc.c index 41b0106..96403a4 100644 --- a/drivers/net/ethernet/ethoc.c +++ b/drivers/net/ethernet/ethoc.c @@ -1241,9 +1241,10 @@ error2: error: mdiobus_unregister(priv->mdio); mdiobus_free(priv->mdio); -free: + if (priv->clk) clk_disable_unprepare(priv->clk); +free: free_netdev(netdev); out: return ret; -- 2.8.1
[toc] | [next] | [standalone]
| From | Max Filippov <jcmvbkbc@gmail.com> |
|---|---|
| Date | 2016-05-22 21:50 +0200 |
| Message-ID | <rBHxU-4H7-7@gated-at.bofh.it> |
| In reply to | #1405033 |
Hi Colin, On Sun, May 22, 2016 at 08:08:18PM +0100, Colin King wrote: > From: Colin Ian King <colin.king@canonical.com> > > priv is assigned to NULL however all the error exit paths to label 'free' > dereference priv, causing a null pointer dereference. > > Examination of the code shows that all error exits via the 'free' > label path occur before priv is assigned to netdev_priv(netdev), hence > there is no need to call clk_disable_unprepare and so the location of > the label should be moved to free_netdev statement to avoid this null > dereference on priv. This description is a bit inaccurate. Indeed all 'goto free' above the 'priv = netdev_priv(netdev);' need to skip 'if (priv->clk)' check, but there are two more 'goto free' below that line, and they look correct now, but after this patch they'll leave the clock enabled. -- Thanks. -- Max
[toc] | [prev] | [next] | [standalone]
| From | Colin Ian King <colin.king@canonical.com> |
|---|---|
| Date | 2016-05-22 23:30 +0200 |
| Message-ID | <rBJ6G-5Ht-15@gated-at.bofh.it> |
| In reply to | #1405038 |
On 22/05/16 20:42, Max Filippov wrote: > Hi Colin, > > On Sun, May 22, 2016 at 08:08:18PM +0100, Colin King wrote: >> From: Colin Ian King <colin.king@canonical.com> >> >> priv is assigned to NULL however all the error exit paths to label 'free' >> dereference priv, causing a null pointer dereference. >> >> Examination of the code shows that all error exits via the 'free' >> label path occur before priv is assigned to netdev_priv(netdev), hence >> there is no need to call clk_disable_unprepare and so the location of >> the label should be moved to free_netdev statement to avoid this null >> dereference on priv. > > This description is a bit inaccurate. Indeed all 'goto free' above the > 'priv = netdev_priv(netdev);' need to skip 'if (priv->clk)' check, but > there are two more 'goto free' below that line, and they look correct > now, but after this patch they'll leave the clock enabled. > Oops, I'll resend a corrected fix tomorrow
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web