[PATCH] PCI: imx6: Fix a "Null pointer dereference" issue

Qianqiang Liu posted 1 patch 2 months, 2 weeks ago
drivers/pci/controller/dwc/pci-imx6.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
[PATCH] PCI: imx6: Fix a "Null pointer dereference" issue
Posted by Qianqiang Liu 2 months, 2 weeks ago
The "resource_list_first_type" function may return NULL, which
will make "entry->offset" dereferences a NULL pointer.

Signed-off-by: Qianqiang Liu <qianqiang.liu@163.com>
---
 drivers/pci/controller/dwc/pci-imx6.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/pci/controller/dwc/pci-imx6.c b/drivers/pci/controller/dwc/pci-imx6.c
index 0dbc333adcff..04e90ba4e7d6 100644
--- a/drivers/pci/controller/dwc/pci-imx6.c
+++ b/drivers/pci/controller/dwc/pci-imx6.c
@@ -1017,13 +1017,14 @@ static u64 imx_pcie_cpu_addr_fixup(struct dw_pcie *pcie, u64 cpu_addr)
 	struct imx_pcie *imx_pcie = to_imx_pcie(pcie);
 	struct dw_pcie_rp *pp = &pcie->pp;
 	struct resource_entry *entry;
-	unsigned int offset;
+	unsigned int offset = 0;
 
 	if (!(imx_pcie->drvdata->flags & IMX_PCIE_FLAG_CPU_ADDR_FIXUP))
 		return cpu_addr;
 
 	entry = resource_list_first_type(&pp->bridge->windows, IORESOURCE_MEM);
-	offset = entry->offset;
+	if (entry)
+		offset = entry->offset;
 
 	return (cpu_addr - offset);
 }
-- 
2.39.2
Re: [PATCH] PCI: imx6: Fix a "Null pointer dereference" issue
Posted by Bjorn Helgaas 2 months, 2 weeks ago
On Wed, Sep 11, 2024 at 08:50:57PM +0800, Qianqiang Liu wrote:
> The "resource_list_first_type" function may return NULL, which
> will make "entry->offset" dereferences a NULL pointer.
> 
> Signed-off-by: Qianqiang Liu <qianqiang.liu@163.com>
> ---
>  drivers/pci/controller/dwc/pci-imx6.c | 5 +++--
>  1 file changed, 3 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/pci/controller/dwc/pci-imx6.c b/drivers/pci/controller/dwc/pci-imx6.c
> index 0dbc333adcff..04e90ba4e7d6 100644
> --- a/drivers/pci/controller/dwc/pci-imx6.c
> +++ b/drivers/pci/controller/dwc/pci-imx6.c
> @@ -1017,13 +1017,14 @@ static u64 imx_pcie_cpu_addr_fixup(struct dw_pcie *pcie, u64 cpu_addr)
>  	struct imx_pcie *imx_pcie = to_imx_pcie(pcie);
>  	struct dw_pcie_rp *pp = &pcie->pp;
>  	struct resource_entry *entry;
> -	unsigned int offset;
> +	unsigned int offset = 0;
>  
>  	if (!(imx_pcie->drvdata->flags & IMX_PCIE_FLAG_CPU_ADDR_FIXUP))
>  		return cpu_addr;
>  
>  	entry = resource_list_first_type(&pp->bridge->windows, IORESOURCE_MEM);
> -	offset = entry->offset;
> +	if (entry)
> +		offset = entry->offset;
>  
>  	return (cpu_addr - offset);
>  }

I made the edit I proposed here:
https://lore.kernel.org/r/20240911140721.GA630378@bhelgaas

Please double-check it at:
https://git.kernel.org/pub/scm/linux/kernel/git/pci/pci.git/commit/?id=c2699778e6be
Re: [PATCH] PCI: imx6: Fix a "Null pointer dereference" issue
Posted by Frank Li 2 months, 2 weeks ago
On Wed, Sep 11, 2024 at 09:16:58AM -0500, Bjorn Helgaas wrote:
> On Wed, Sep 11, 2024 at 08:50:57PM +0800, Qianqiang Liu wrote:
> > The "resource_list_first_type" function may return NULL, which
> > will make "entry->offset" dereferences a NULL pointer.
> >
> > Signed-off-by: Qianqiang Liu <qianqiang.liu@163.com>
> > ---
> >  drivers/pci/controller/dwc/pci-imx6.c | 5 +++--
> >  1 file changed, 3 insertions(+), 2 deletions(-)
> >
> > diff --git a/drivers/pci/controller/dwc/pci-imx6.c b/drivers/pci/controller/dwc/pci-imx6.c
> > index 0dbc333adcff..04e90ba4e7d6 100644
> > --- a/drivers/pci/controller/dwc/pci-imx6.c
> > +++ b/drivers/pci/controller/dwc/pci-imx6.c
> > @@ -1017,13 +1017,14 @@ static u64 imx_pcie_cpu_addr_fixup(struct dw_pcie *pcie, u64 cpu_addr)
> >  	struct imx_pcie *imx_pcie = to_imx_pcie(pcie);
> >  	struct dw_pcie_rp *pp = &pcie->pp;
> >  	struct resource_entry *entry;
> > -	unsigned int offset;
> > +	unsigned int offset = 0;
> >
> >  	if (!(imx_pcie->drvdata->flags & IMX_PCIE_FLAG_CPU_ADDR_FIXUP))
> >  		return cpu_addr;
> >
> >  	entry = resource_list_first_type(&pp->bridge->windows, IORESOURCE_MEM);
> > -	offset = entry->offset;
> > +	if (entry)
> > +		offset = entry->offset;
> >
> >  	return (cpu_addr - offset);
> >  }
>
> I made the edit I proposed here:
> https://lore.kernel.org/r/20240911140721.GA630378@bhelgaas
>
> Please double-check it at:
> https://git.kernel.org/pub/scm/linux/kernel/git/pci/pci.git/commit/?id=c2699778e6be

It is good.
Frank