]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
bnge: Fix NULL pointer dereference in aux device release
authorAlok Tiwari <alok.a.tiwari@oracle.com>
Fri, 31 Jul 2026 19:22:59 +0000 (12:22 -0700)
committerJakub Kicinski <kuba@kernel.org>
Tue, 4 Aug 2026 01:12:50 +0000 (18:12 -0700)
commit1cb4298810e27e037d3ca07286ecbb97e89ba58d
tree7b7771224439ece3c5e55e2013018943bb269a7a
parent1f428e30947395d9b9aacee03e25a4e6cfcad7a4
bnge: Fix NULL pointer dereference in aux device release

If allocation of auxr_dev fails during auxiliary device setup, the error
path calls auxiliary_device_uninit(), which eventually invokes
bnge_aux_dev_release().

The release callback unconditionally dereferences aux_priv->auxr_dev->pdev
to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated
on this failure path, the dereference results in a NULL pointer exception

Retrieve the parent bnge_dev from the auxiliary device's parent instead of
auxr_dev, and free auxr_dev only when it was successfully allocated. This
allows the release callback to correctly clean up partially initialized
auxiliary devices.

Fixes: 8ac050ec3b1c ("bng_en: Add RoCE aux device support")
Signed-off-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Reviewed-by: Bhargava Marreddy <bhargava.marreddy@broadcom.com>
Link: https://patch.msgid.link/20260731192301.1427645-1-alok.a.tiwari@oracle.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/ethernet/broadcom/bnge/bnge_auxr.c