]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
idpf: nullify pointers after they are freed
authorLi Li <boolli@google.com>
Fri, 23 Jan 2026 06:58:06 +0000 (06:58 +0000)
committerTony Nguyen <anthony.l.nguyen@intel.com>
Wed, 25 Feb 2026 19:43:57 +0000 (11:43 -0800)
rss_data->rss_key needs to be nullified after it is freed.
Checks like "if (!rss_data->rss_key)" in the code could fail
if it is not nullified.

Tested: built and booted the kernel.

Fixes: 83f38f210b85 ("idpf: Fix RSS LUT NULL pointer crash on early ethtool operations")
Signed-off-by: Li Li <boolli@google.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Tested-by: Samuel Salin <Samuel.salin@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
drivers/net/ethernet/intel/idpf/idpf_lib.c

index 94da5fbd56f1e13753d8209b7b0db02900551d70..7ce6a0e4acb6a49ba51fc5fdcbbbb9074157eb0f 100644 (file)
@@ -1320,6 +1320,7 @@ static struct idpf_vport *idpf_vport_alloc(struct idpf_adapter *adapter,
 
 free_rss_key:
        kfree(rss_data->rss_key);
+       rss_data->rss_key = NULL;
 free_qreg_chunks:
        idpf_vport_deinit_queue_reg_chunks(adapter->vport_config[idx]);
 free_vector_idxs: