Thread (4 messages) flat view 4 messages, 3 authors, 2015-08-14

RE: [Intel-wired-lan] [PATCH v2] e1000e: Modify tx/rx configurations to avoid null pointer dereferences in e1000_open

From: Brown, Aaron F <hidden>
Date: 2015-08-14 23:28:39
Also in: intel-wired-lan, lkml

From: Intel-wired-lan [mailto:intel-wired-lan-bounces@lists.osuosl.org] On
Behalf Of Jia-Ju Bai
Sent: Wednesday, August 05, 2015 3:16 AM
To: Kirsher, Jeffrey T; Brandeburg, Jesse
Cc: netdev@vger.kernel.org; Jia-Ju Bai; intel-wired-lan@lists.osuosl.org;
linux-kernel@vger.kernel.org
Subject: [Intel-wired-lan] [PATCH v2] e1000e: Modify tx/rx configurations
to avoid null pointer dereferences in e1000_open

When e1000e_setup_rx_resources is failed in e1000_open,
e1000e_free_tx_resources in "err_setup_rx" segment is executed.
"writel(0, tx_ring->head)" statement in e1000_clean_tx_ring
in e1000e_free_tx_resources will cause a null poonter dereference(crash),
because "tx_ring->head" is only assigned in e1000_configure_tx
in e1000_configure, but it is after e1000e_setup_rx_resources.

This patch moves head/tail register writing to e1000_configure_tx/rx,
which can fix this problem. It is inspired by igb_configure_tx_ring
in the igb driver.

Specially, thank Alexander Duyck for his valuable suggestion.

Signed-off-by: Jia-Ju Bai <redacted>
---
 drivers/net/ethernet/intel/e1000e/netdev.c |   24 ++++++++++++-----------
-
 1 file changed, 12 insertions(+), 12 deletions(-)
Tested-by: Aaron Brown <redacted>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help