750-v6.5-15-net-ethernet-mtk_eth_soc-fix-NULL-pointer-on-hw-rese.patch 1.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152
  1. From 3b12f42772c26869d60398c1710aa27b27cd945c Mon Sep 17 00:00:00 2001
  2. From: Daniel Golle <[email protected]>
  3. Date: Mon, 21 Aug 2023 17:12:44 +0100
  4. Subject: [PATCH 109/250] net: ethernet: mtk_eth_soc: fix NULL pointer on hw
  5. reset
  6. When a hardware reset is triggered on devices not initializing WED the
  7. calls to mtk_wed_fe_reset and mtk_wed_fe_reset_complete dereference a
  8. pointer on uninitialized stack memory.
  9. Break out of both functions in case a hw_list entry is 0.
  10. Fixes: 08a764a7c51b ("net: ethernet: mtk_wed: add reset/reset_complete callbacks")
  11. Signed-off-by: Daniel Golle <[email protected]>
  12. Reviewed-by: Simon Horman <[email protected]>
  13. Acked-by: Lorenzo Bianconi <[email protected]>
  14. Link: https://lore.kernel.org/r/5465c1609b464cc7407ae1530c40821dcdf9d3e6.1692634266.git.daniel@makrotopia.org
  15. Signed-off-by: Jakub Kicinski <[email protected]>
  16. ---
  17. drivers/net/ethernet/mediatek/mtk_wed.c | 12 ++++++++++--
  18. 1 file changed, 10 insertions(+), 2 deletions(-)
  19. --- a/drivers/net/ethernet/mediatek/mtk_wed.c
  20. +++ b/drivers/net/ethernet/mediatek/mtk_wed.c
  21. @@ -214,9 +214,13 @@ void mtk_wed_fe_reset(void)
  22. for (i = 0; i < ARRAY_SIZE(hw_list); i++) {
  23. struct mtk_wed_hw *hw = hw_list[i];
  24. - struct mtk_wed_device *dev = hw->wed_dev;
  25. + struct mtk_wed_device *dev;
  26. int err;
  27. + if (!hw)
  28. + break;
  29. +
  30. + dev = hw->wed_dev;
  31. if (!dev || !dev->wlan.reset)
  32. continue;
  33. @@ -237,8 +241,12 @@ void mtk_wed_fe_reset_complete(void)
  34. for (i = 0; i < ARRAY_SIZE(hw_list); i++) {
  35. struct mtk_wed_hw *hw = hw_list[i];
  36. - struct mtk_wed_device *dev = hw->wed_dev;
  37. + struct mtk_wed_device *dev;
  38. +
  39. + if (!hw)
  40. + break;
  41. + dev = hw->wed_dev;
  42. if (!dev || !dev->wlan.reset_complete)
  43. continue;