From nobody Sun Dec 14 12:13:26 2025 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=kernel.org ARC-Seal: i=1; a=rsa-sha256; t=1762726119; cv=none; d=zohomail.com; s=zohoarc; b=BukQA7wDJ8qYjJEAI1iBtwO3aYRzW7Qw6MuWEWj5cQkWuiu05nzR906QqUGZs1C08YpQxj1g9Wmbu+WuZcEQgWkX95lFfw/a7omJdOnCRcU6YatSY9Jt0fbPe1tNDWl9aZqap1gDAEiIDepaptfd+bBoV5S7x2qrlq4QATu5ulg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1762726119; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NOafgaE9MFpSlVrAOw5dKfK8Cc7ilosa5J/H1fFYLKk=; b=PJ8GV8rX38+QY7p5j+hH/jr4HTbt/P8NwE/52M45eHrLXhsEpbnt5O4oW14PWIvDyZQEo+wgquzOFbdugEKBz8+hIrsodU89s2SZcJxXrAbv1Iry4RrPJElIA6uMjW7AZmdqrpfhyIoC2qW++eQy+nbVF+WTCEb2MET59cj2V+U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1762726119026270.23951787910903; Sun, 9 Nov 2025 14:08:39 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vIDYx-0007dG-Uv; Sun, 09 Nov 2025 17:07:08 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vIDYv-0007ac-37 for qemu-devel@nongnu.org; Sun, 09 Nov 2025 17:07:05 -0500 Received: from tor.source.kernel.org ([2600:3c04:e001:324:0:1991:8:25]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vIDYs-0005sP-Sc for qemu-devel@nongnu.org; Sun, 09 Nov 2025 17:07:04 -0500 Received: from smtp.kernel.org (transwarp.subspace.kernel.org [100.75.92.58]) by tor.source.kernel.org (Postfix) with ESMTP id C264C60008; Sun, 9 Nov 2025 22:06:59 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5F28DC4CEF8; Sun, 9 Nov 2025 22:06:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1762726019; bh=FjRRjfXkVql2NimzOsvAxPczRCiES2X1ZlT8g/OPtes=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=g79Fbf9pK10YZpxp0yRqjdUmiGLfXS43ceIdgeK7AQpisuxr7sUpvDAlE07muDju/ eBkL22bFfWbZvhel1ssNyqt2KgzktOiRnqOcmF3fMzY5GFrHQDu9LWt/yGiQSq4bvk kWOmDucMb3S3uTH5sVPA8ufnbtLqZCq/S2UI03d0jfvdUXJZXtKxJo/5G6yaujrwQf tt+AtZ2P1pJRxVf4jMM2It6CPlqqREQECsvsqja27MdHAAFX0pKJmqCA/2zq0HDkNL i3O5ixxFxa1Vo25nMQzWaP7+j6ZDc7bt4MYBDg2g7qu2T2RTsekinWjmd8DI1a2vue LcoGM1NyWiHVA== From: deller@kernel.org To: Richard Henderson , qemu-devel@nongnu.org Cc: Soumyajyotii Ssarkar , Helge Deller Subject: [PULL 1/7] ncr710: Fix potential null pointer dereference Date: Sun, 9 Nov 2025 23:06:48 +0100 Message-ID: <20251109220654.46718-2-deller@kernel.org> X-Mailer: git-send-email 2.51.1 In-Reply-To: <20251109220654.46718-1-deller@kernel.org> References: <20251109220654.46718-1-deller@kernel.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=2600:3c04:e001:324:0:1991:8:25; envelope-from=deller@kernel.org; helo=tor.source.kernel.org X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @kernel.org) X-ZM-MESSAGEID: 1762726120640158500 Content-Type: text/plain; charset="utf-8" From: Soumyajyotii Ssarkar The code dereferences s->current before checking if it is NULL. Move the null check before the dereference to prevent potential crashes. This issue could occur if s->current is NULL when the function reaches the "Host adapter (re)connected" path, though this should not normally happen during correct operation. Reported-by: Stefan Hajnoczi Reported-by: GuoHan Zhao Suggested-by: GuoHan Zhao Signed-off-by: Soumyajyotii Ssarkar Reviewed-by: Helge Deller Signed-off-by: Helge Deller --- hw/scsi/ncr53c710.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/hw/scsi/ncr53c710.c b/hw/scsi/ncr53c710.c index ade951b1d1..a35c41b67f 100644 --- a/hw/scsi/ncr53c710.c +++ b/hw/scsi/ncr53c710.c @@ -832,12 +832,11 @@ void ncr710_transfer_data(SCSIRequest *req, uint32_t = len) } =20 /* Host adapter (re)connected */ - s->current->dma_len =3D len; s->command_complete =3D NCR710_CMD_DATA_READY; - if (!s->current) { return; } + s->current->dma_len =3D len; =20 if (s->waiting) { s->scntl1 |=3D NCR710_SCNTL1_CON; --=20 2.51.1