]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
bnxt_en: Fix NULL pointer dereference
authorKyle Meyer <kyle.meyer@hpe.com>
Fri, 5 Jun 2026 22:25:24 +0000 (17:25 -0500)
committerJakub Kicinski <kuba@kernel.org>
Wed, 10 Jun 2026 00:52:46 +0000 (17:52 -0700)
PCIe errors detected by a Root Port or Downstream Port cause error
recovery services to run on all subordinate devices regardless of
administrative state.

The .error_detected() callback, bnxt_io_error_detected(), disables
and synchronizes IRQs via bnxt_disable_int_sync(), which calls
bnxt_cp_num_to_irq_num() to map completion rings to IRQs using
bp->bnapi.

Since bp->bnapi is allocated on NIC open and freed on NIC close, PCIe
error recovery on a closed NIC can dereference a NULL pointer.

Check if bp->bnapi is NULL before disabling and synchronizing IRQs.

Fixes: e5811b8c09df ("bnxt_en: Add IRQ remapping logic.")
Cc: stable@vger.kernel.org
Signed-off-by: Kyle Meyer <kyle.meyer@hpe.com>
Reviewed-by: Pavan Chebbi <pavan.chebbi@broadcom.com>
Link: https://patch.msgid.link/aiNM1CY2-StPilxW@hpe.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/ethernet/broadcom/bnxt/bnxt.c

index 35e1f8f663c78ed757b872028ff13d1b19f98e7a..c999f9733326a59df1c19c482b802e62fe1f833c 100644 (file)
@@ -5748,7 +5748,7 @@ static void bnxt_disable_int_sync(struct bnxt *bp)
 {
        int i;
 
-       if (!bp->irq_tbl)
+       if (!bp->irq_tbl || !bp->bnapi)
                return;
 
        atomic_inc(&bp->intr_sem);