[PATCH] AMD_SFH: Fix potential NULL pointer dereference

Subsystems: amd sensor fusion hub driver, hid core layer, the rest

STALE1797d

5 messages, 4 authors, 2021-09-16 · open the first message on its own page

[PATCH] AMD_SFH: Fix potential NULL pointer dereference

From: Evgeny Novikov <hidden>
Date: 2021-06-01 16:38:09

devm_add_action_or_reset() can suddenly invoke amd_mp2_pci_remove() at
registration that will cause NULL pointer dereference since
corresponding data is not initialized yet. The patch moves
initialization of data before devm_add_action_or_reset().

Found by Linux Driver Verification project (linuxtesting.org).

Signed-off-by: Evgeny Novikov <redacted>
---
 drivers/hid/amd-sfh-hid/amd_sfh_pcie.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
index ddecc84fd6f0..8394565c4d01 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
@@ -160,11 +160,16 @@ static int amd_mp2_pci_probe(struct pci_dev *pdev, const struct pci_device_id *i
 		rc = pci_set_dma_mask(pdev, DMA_BIT_MASK(32));
 		return rc;
 	}
+
+	rc = amd_sfh_hid_client_init(privdata);
+	if (rc)
+		return rc;
+
 	rc = devm_add_action_or_reset(&pdev->dev, amd_mp2_pci_remove, privdata);
 	if (rc)
 		return rc;
 
-	return amd_sfh_hid_client_init(privdata);
+	return 0;
 }
 
 static const struct pci_device_id amd_mp2_pci_tbl[] = {
-- 
2.26.2

Re: [PATCH] AMD_SFH: Fix potential NULL pointer dereference

From: Jiri Kosina <jikos@kernel.org>
Date: 2021-09-15 14:58:48

On Tue, 1 Jun 2021, Evgeny Novikov wrote:
devm_add_action_or_reset() can suddenly invoke amd_mp2_pci_remove() at
registration that will cause NULL pointer dereference since
corresponding data is not initialized yet. The patch moves
initialization of data before devm_add_action_or_reset().

Found by Linux Driver Verification project (linuxtesting.org).

Signed-off-by: Evgeny Novikov <redacted>
Nehal, Basavaraj, could you please Review/Ack this one?

Thanks,

-- 
Jiri Kosina
SUSE Labs

RE: [PATCH] AMD_SFH: Fix potential NULL pointer dereference

From: Shah, Nehal-bakulchandra <hidden>
Date: 2021-09-15 17:32:19

Adding Basavaraj

-----Original Message-----
From: Jiri Kosina <jikos@kernel.org> 
Sent: Wednesday, September 15, 2021 8:28 PM
To: Evgeny Novikov <redacted>
Cc: Shah, Nehal-bakulchandra <redacted>; Sandeep Singh <redacted>; Benjamin Tissoires <redacted>; linux-input@vger.kernel.org; linux-kernel@vger.kernel.org; ldv-project@linuxtesting.org
Subject: Re: [PATCH] AMD_SFH: Fix potential NULL pointer dereference

On Tue, 1 Jun 2021, Evgeny Novikov wrote:
devm_add_action_or_reset() can suddenly invoke amd_mp2_pci_remove() at 
registration that will cause NULL pointer dereference since 
corresponding data is not initialized yet. The patch moves 
initialization of data before devm_add_action_or_reset().

Found by Linux Driver Verification project (linuxtesting.org).

Signed-off-by: Evgeny Novikov <redacted>
Nehal, Basavaraj, could you please Review/Ack this one?

Thanks,

--
Jiri Kosina
SUSE Labs

Re: [PATCH] AMD_SFH: Fix potential NULL pointer dereference

From: Basavaraj Natikar <hidden>
Date: 2021-09-16 05:59:50

On 9/15/2021 11:02 PM, Shah, Nehal-bakulchandra wrote:
Adding Basavaraj

-----Original Message-----
From: Jiri Kosina <jikos@kernel.org> 
Sent: Wednesday, September 15, 2021 8:28 PM
To: Evgeny Novikov <redacted>
Cc: Shah, Nehal-bakulchandra <redacted>; Sandeep Singh <redacted>; Benjamin Tissoires <redacted>; linux-input@vger.kernel.org; linux-kernel@vger.kernel.org; ldv-project@linuxtesting.org
Subject: Re: [PATCH] AMD_SFH: Fix potential NULL pointer dereference

On Tue, 1 Jun 2021, Evgeny Novikov wrote:
quoted
devm_add_action_or_reset() can suddenly invoke amd_mp2_pci_remove() at 
registration that will cause NULL pointer dereference since 
corresponding data is not initialized yet. The patch moves 
initialization of data before devm_add_action_or_reset().

Found by Linux Driver Verification project (linuxtesting.org).

Signed-off-by: Evgeny Novikov <redacted>
Nehal, Basavaraj, could you please Review/Ack this one?
Patch looks good to me. Acked-by: Basavaraj Natikar [off-list ref]

Re: [PATCH] AMD_SFH: Fix potential NULL pointer dereference

From: Jiri Kosina <jikos@kernel.org>
Date: 2021-09-16 07:15:42

On Tue, 1 Jun 2021, Evgeny Novikov wrote:
devm_add_action_or_reset() can suddenly invoke amd_mp2_pci_remove() at
registration that will cause NULL pointer dereference since
corresponding data is not initialized yet. The patch moves
initialization of data before devm_add_action_or_reset().

Found by Linux Driver Verification project (linuxtesting.org).

Signed-off-by: Evgeny Novikov <redacted>
Applied, thank you.

-- 
Jiri Kosina
SUSE Labs
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help