]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
octeon_ep_vf: add NULL check for napi_build_skb()
authorDavid Carlier <devnexen@gmail.com>
Thu, 9 Apr 2026 18:40:09 +0000 (19:40 +0100)
committerJakub Kicinski <kuba@kernel.org>
Mon, 13 Apr 2026 22:40:49 +0000 (15:40 -0700)
napi_build_skb() can return NULL on allocation failure. In
__octep_vf_oq_process_rx(), the result is used directly without a NULL
check in both the single-buffer and multi-fragment paths, leading to a
NULL pointer dereference.

Add NULL checks after both napi_build_skb() calls, properly advancing
descriptors and consuming remaining fragments on failure.

Fixes: 1cd3b407977c ("octeon_ep_vf: add Tx/Rx processing and interrupt support")
Cc: stable@vger.kernel.org
Signed-off-by: David Carlier <devnexen@gmail.com>
Link: https://patch.msgid.link/20260409184009.930359-3-devnexen@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c

index 7bd1b9b8d7f5a1662124a87f05f3f8af41dac44b..d9824740824239c90120054d601d4dd4ae6d3af9 100644 (file)
@@ -414,10 +414,15 @@ static int __octep_vf_oq_process_rx(struct octep_vf_device *oct,
                        data_offset = OCTEP_VF_OQ_RESP_HW_SIZE;
                        rx_ol_flags = 0;
                }
-               rx_bytes += buff_info->len;
-
                if (buff_info->len <= oq->max_single_buffer_size) {
                        skb = napi_build_skb((void *)resp_hw, PAGE_SIZE);
+                       if (!skb) {
+                               oq->stats->alloc_failures++;
+                               desc_used++;
+                               read_idx = octep_vf_oq_next_idx(oq, read_idx);
+                               continue;
+                       }
+                       rx_bytes += buff_info->len;
                        skb_reserve(skb, data_offset);
                        skb_put(skb, buff_info->len);
                        desc_used++;
@@ -427,6 +432,27 @@ static int __octep_vf_oq_process_rx(struct octep_vf_device *oct,
                        u16 data_len;
 
                        skb = napi_build_skb((void *)resp_hw, PAGE_SIZE);
+                       if (!skb) {
+                               oq->stats->alloc_failures++;
+                               desc_used++;
+                               read_idx = octep_vf_oq_next_idx(oq, read_idx);
+                               data_len = buff_info->len - oq->max_single_buffer_size;
+                               while (data_len) {
+                                       dma_unmap_page(oq->dev, oq->desc_ring[read_idx].buffer_ptr,
+                                                      PAGE_SIZE, DMA_FROM_DEVICE);
+                                       buff_info = (struct octep_vf_rx_buffer *)
+                                                   &oq->buff_info[read_idx];
+                                       buff_info->page = NULL;
+                                       if (data_len < oq->buffer_size)
+                                               data_len = 0;
+                                       else
+                                               data_len -= oq->buffer_size;
+                                       desc_used++;
+                                       read_idx = octep_vf_oq_next_idx(oq, read_idx);
+                               }
+                               continue;
+                       }
+                       rx_bytes += buff_info->len;
                        skb_reserve(skb, data_offset);
                        /* Head fragment includes response header(s);
                         * subsequent fragments contains only data.