Thread (4 messages) read the whole thread 4 messages, 2 authors, 2021-05-26

Re: [PATCH] media: cobalt: fix null-ptr-deref when there is no PCI bridge

From: Hans Verkuil <hidden>
Date: 2021-05-05 09:18:30
Also in: lkml

On 24/04/2021 02:52, Tong Zhang wrote:
the PCI bridge might be NULL, so we'd better check before use it

[    1.870569] RIP: 0010:pcie_bus_link_get_lanes.isra.0+0x26/0x59 [cobalt]
[    1.875880] Call Trace:
[    1.876013]  cobalt_probe.cold+0x1be/0xc11 [cobalt]
[    1.876683]  pci_device_probe+0x10f/0x1c0
How did you test this? With some virtualized PCI bus or something? I'm not sure
how this can happen.

Regards,

	Hans
quoted hunk ↗ jump to hunk
Signed-off-by: Tong Zhang <redacted>
---
 drivers/media/pci/cobalt/cobalt-driver.c | 4 ++++
 1 file changed, 4 insertions(+)
diff --git a/drivers/media/pci/cobalt/cobalt-driver.c b/drivers/media/pci/cobalt/cobalt-driver.c
index 0695078ef812..5687ed4869ac 100644
--- a/drivers/media/pci/cobalt/cobalt-driver.c
+++ b/drivers/media/pci/cobalt/cobalt-driver.c
@@ -189,6 +189,8 @@ void cobalt_pcie_status_show(struct cobalt *cobalt)
 	u32 capa;
 	u16 stat, ctrl;
 
+	if (!pci_bus_dev)
+		return;
 	if (!pci_is_pcie(pci_dev) || !pci_is_pcie(pci_bus_dev))
 		return;
 
@@ -247,6 +249,8 @@ static unsigned pcie_bus_link_get_lanes(struct cobalt *cobalt)
 	struct pci_dev *pci_dev = cobalt->pci_dev->bus->self;
 	u32 link;
 
+	if (!pci_dev)
+		return 0;
 	if (!pci_is_pcie(pci_dev))
 		return 0;
 	pcie_capability_read_dword(pci_dev, PCI_EXP_LNKCAP, &link);
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help