Re: [PATCH net-next] net: phylink: fix NULL pl->pcs dereference during phylink_pcs_poll_start
From: "Russell King (Oracle)" <linux@armlinux.org.uk>
Date: 2022-06-30 14:50:52
On Thu, Jun 30, 2022 at 03:46:54PM +0200, Nicolas Ferre wrote:
Vladimir, Russell, On 29/06/2022 at 21:33, Vladimir Oltean wrote:quoted
The current link mode of the phylink instance may not require an attached PCS. However, phylink_major_config() unconditionally dereferences this potentially NULL pointer when restarting the link poll timer, which will panic the kernel. Fix the problem by checking whether a PCS exists in phylink_pcs_poll_start(), otherwise do nothing. The code prior to the blamed patch also only looked at pcs->poll within an "if (pcs)" block. Fixes: bfac8c490d60 ("net: phylink: disable PCS polling over major configuration") Signed-off-by: Vladimir Oltean <vladimir.oltean@nxp.com> --- drivers/net/phy/phylink.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)diff --git a/drivers/net/phy/phylink.c b/drivers/net/phy/phylink.c index 1a7550f5fdf5..48f0b9b39491 100644 --- a/drivers/net/phy/phylink.c +++ b/drivers/net/phy/phylink.c@@ -766,7 +766,7 @@ static void phylink_pcs_poll_stop(struct phylink *pl) static void phylink_pcs_poll_start(struct phylink *pl) { - if (pl->pcs->poll && pl->cfg_link_an_mode == MLO_AN_INBAND) + if (pl->pcs && pl->pcs->poll && pl->cfg_link_an_mode == MLO_AN_INBAND) mod_timer(&pl->link_poll, jiffies + HZ); }Fixes the NULL pointer on my boards: Tested-by: Nicolas Ferre <nicolas.ferre@microchip.com> # on sam9x60ek
Thanks all, hopefully it'll get applied to net-next soon. Sadly, this slipped through my testing, as the only platform I have access to at the moment always supplies a PCS (mvneta based) so there's no way my testing would ever have caught this. Sorry for the problems. -- RMK's Patch system: https://www.armlinux.org.uk/developer/patches/ FTTP is here! 40Mbps down 10Mbps up. Decent connectivity at last!