]> www.infradead.org Git - users/jedix/linux-maple.git/commitdiff
i40evf: check for msix_entries null dereference
authorAlan Brady <alan.brady@intel.com>
Tue, 8 Nov 2016 21:05:05 +0000 (13:05 -0800)
committerDhaval Giani <dhaval.giani@oracle.com>
Wed, 8 Mar 2017 00:41:18 +0000 (19:41 -0500)
Orabug: 24568124

It is possible for msix_entries to be freed by a previous suspend/remove
before a VF is closed.  This patch fixes the issue by checking for NULL
before dereferencing msix_entries and returning early in the case where
it is NULL within the i40evf_close code path.  Without this patch it is
possible to trigger a kernel panic through NULL dereference.

Change-ID: I92a2746e82533a889e25f91578eac9abd0388ae2
Signed-off-by: Alan Brady <alan.brady@intel.com>
Tested-by: Andrew Bowers <andrewx.bowers@intel.com>
Signed-off-by: Jeff Kirsher <jeffrey.t.kirsher@intel.com>
(cherry picked from commit 47d2a5d8279dcdcaec2c67b3d2c72cfa62979c58)
Signed-off-by: Brian Maly <brian.maly@oracle.com>
Signed-off-by: Dhaval Giani <dhaval.giani@oracle.com>
drivers/net/ethernet/intel/i40evf/i40evf_main.c

index 59299b99d3e107dfc2780515d06a4e4b0c458107..426a766f7442b32fb09f0dbd1dd35e0dc9638383 100644 (file)
@@ -633,6 +633,9 @@ static void i40evf_free_traffic_irqs(struct i40evf_adapter *adapter)
 {
        int vector, irq_num, q_vectors;
 
+       if (!adapter->msix_entries)
+               return;
+
        q_vectors = adapter->num_msix_vectors - NONQ_VECS;
 
        for (vector = 0; vector < q_vectors; vector++) {
@@ -1445,6 +1448,9 @@ static void i40evf_free_q_vectors(struct i40evf_adapter *adapter)
  **/
 void i40evf_reset_interrupt_capability(struct i40evf_adapter *adapter)
 {
+       if (!adapter->msix_entries)
+               return;
+
        pci_disable_msix(adapter->pdev);
        kfree(adapter->msix_entries);
        adapter->msix_entries = NULL;