Thread (7 messages) flat view 7 messages, 6 authors, 12d ago

Re: [PATCH net] net: macb: fix NULL pointer dereference on unbind with fixed-link

From: Xuanqiang Luo <hidden>
Date: 2026-09-03 02:17:32
Also in: lkml

在 2026/9/2 18:28, Vineeth Karumanchi 写道:
When the device tree describes a fixed-link and has no "mdio" child
node, macb_mii_init() returns early without allocating the MDIO bus,
leaving bp->mii_bus as NULL.

Two cleanup paths then dereference this NULL bus:

1. On driver unbind, macb_remove() unconditionally calls
    mdiobus_unregister(bp->mii_bus), which oopses:

   Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8
   pc : mdiobus_unregister+0x14/0xa4
   lr : macb_remove+0x38/0xa4
   Call trace:
    mdiobus_unregister+0x14/0xa4 (P)
    macb_remove+0x38/0xa4
    platform_remove+0x20/0x30
    device_release_driver_internal+0x1c8/0x224
    unbind_store+0xb4/0xbc

2. On the probe error path in macb_probe(), reached when
    macb_mii_init() has succeeded but a subsequent step fails, the
    err_out_unregister_mdio label runs the same unconditional cleanup.

mdiobus_unregister() and mdiobus_free() do not guard against a NULL
bus, so guard the calls in both macb_remove() and the probe error
path.

Fixes: d0c3601f2c4e ("net: macb: Avoid 20s boot delay by skipping MDIO bus registration for fixed-link PHY")
Signed-off-by: Vineeth Karumanchi <redacted>
Reviewed-by: Xuanqiang Luo <redacted>

Thanks,
Xuanqiang
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help