]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
bnge: Fix NULL pointer dereference in aux device release
authorAlok Tiwari <alok.a.tiwari@oracle.com>
Fri, 31 Jul 2026 19:22:59 +0000 (12:22 -0700)
committerJakub Kicinski <kuba@kernel.org>
Tue, 4 Aug 2026 01:12:50 +0000 (18:12 -0700)
If allocation of auxr_dev fails during auxiliary device setup, the error
path calls auxiliary_device_uninit(), which eventually invokes
bnge_aux_dev_release().

The release callback unconditionally dereferences aux_priv->auxr_dev->pdev
to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated
on this failure path, the dereference results in a NULL pointer exception

Retrieve the parent bnge_dev from the auxiliary device's parent instead of
auxr_dev, and free auxr_dev only when it was successfully allocated. This
allows the release callback to correctly clean up partially initialized
auxiliary devices.

Fixes: 8ac050ec3b1c ("bng_en: Add RoCE aux device support")
Signed-off-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Reviewed-by: Bhargava Marreddy <bhargava.marreddy@broadcom.com>
Link: https://patch.msgid.link/20260731192301.1427645-1-alok.a.tiwari@oracle.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/ethernet/broadcom/bnge/bnge_auxr.c

index 67e93e17d4d9f1c06681ade03066ecad63e3d4b4..0955b488b6fea087c3300513ee03ecf322a271a9 100644 (file)
@@ -141,12 +141,15 @@ static void bnge_aux_dev_release(struct device *dev)
 {
        struct bnge_auxr_priv *aux_priv =
                        container_of(dev, struct bnge_auxr_priv, aux_dev.dev);
-       struct bnge_dev *bd = pci_get_drvdata(aux_priv->auxr_dev->pdev);
+       struct bnge_auxr_dev *auxr_dev = aux_priv->auxr_dev;
+       struct bnge_dev *bd = pci_get_drvdata(to_pci_dev(dev->parent));
 
        ida_free(&bnge_aux_dev_ids, aux_priv->id);
-       kfree(aux_priv->auxr_dev->auxr_info);
+       if (auxr_dev) {
+               kfree(auxr_dev->auxr_info);
+               kfree(auxr_dev);
+       }
        bd->auxr_dev = NULL;
-       kfree(aux_priv->auxr_dev);
        kfree(aux_priv);
        bd->aux_priv = NULL;
 }