drivers/dma/ti/k3-udma-glue.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-)
From: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
If devm_kcalloc() for rx_chn->flows fails in a channel request function,
the error path calls k3_udma_glue_release_rx_chn(), which dereferences
the NULL rx_chn->flows pointer in k3_udma_glue_release_rx_flow().
Skip the flow release loop in k3_udma_glue_release_rx_chn() when
rx_chn->flows is not allocated.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: d70241913413 ("dmaengine: ti: k3-udma: Add glue layer for non DMAengine users")
Cc: stable@vger.kernel.org
Reported-by: Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
Signed-off-by: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
---
v3: guard the flow release loop in k3_udma_glue_release_rx_chn() instead
of reordering the flow_num assignment. Covers all error paths in both
request functions.
v2: https://lore.kernel.org/all/20251006124258.1132312-1-Pavel.Zhigulin@kaspersky.com/
drivers/dma/ti/k3-udma-glue.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/dma/ti/k3-udma-glue.c b/drivers/dma/ti/k3-udma-glue.c
index 4f1aeb81e9c7..a739e60b0764 100644
--- a/drivers/dma/ti/k3-udma-glue.c
+++ b/drivers/dma/ti/k3-udma-glue.c
@@ -1103,8 +1103,9 @@ void k3_udma_glue_release_rx_chn(struct k3_udma_glue_rx_channel *rx_chn)
rx_chn->psil_paired = false;
}
- for (i = 0; i < rx_chn->flow_num; i++)
- k3_udma_glue_release_rx_flow(rx_chn, i);
+ if (rx_chn->flows)
+ for (i = 0; i < rx_chn->flow_num; i++)
+ k3_udma_glue_release_rx_flow(rx_chn, i);
if (xudma_rflow_is_gp(rx_chn->common.udmax, rx_chn->flow_id_base))
xudma_free_gp_rflow_range(rx_chn->common.udmax,
--
2.43.0
On Wed, 12 Aug 2026 08:34:26 +0300, Alexander.Chesnokov@kaspersky.com wrote:
> If devm_kcalloc() for rx_chn->flows fails in a channel request function,
> the error path calls k3_udma_glue_release_rx_chn(), which dereferences
> the NULL rx_chn->flows pointer in k3_udma_glue_release_rx_flow().
>
> Skip the flow release loop in k3_udma_glue_release_rx_chn() when
> rx_chn->flows is not allocated.
>
> [...]
Applied, thanks!
[1/1] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
commit: 0294b6dd515256c03ea2dbf508ddd3826d788579
Best regards,
--
~Vinod
On Wed, Aug 12, 2026 at 08:34:26AM +0300, Alexander.Chesnokov@kaspersky.com wrote:
> From: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
>
> If devm_kcalloc() for rx_chn->flows fails in a channel request function,
> the error path calls k3_udma_glue_release_rx_chn(), which dereferences
> the NULL rx_chn->flows pointer in k3_udma_glue_release_rx_flow().
>
> Skip the flow release loop in k3_udma_glue_release_rx_chn() when
> rx_chn->flows is not allocated.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: d70241913413 ("dmaengine: ti: k3-udma: Add glue layer for non DMAengine users")
> Cc: stable@vger.kernel.org
> Reported-by: Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
> Signed-off-by: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
> ---
Reviewed-by: Frank Li <Frank.Li@nxp.com>
>
> v3: guard the flow release loop in k3_udma_glue_release_rx_chn() instead
> of reordering the flow_num assignment. Covers all error paths in both
> request functions.
> v2: https://lore.kernel.org/all/20251006124258.1132312-1-Pavel.Zhigulin@kaspersky.com/
>
> drivers/dma/ti/k3-udma-glue.c | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/dma/ti/k3-udma-glue.c b/drivers/dma/ti/k3-udma-glue.c
> index 4f1aeb81e9c7..a739e60b0764 100644
> --- a/drivers/dma/ti/k3-udma-glue.c
> +++ b/drivers/dma/ti/k3-udma-glue.c
> @@ -1103,8 +1103,9 @@ void k3_udma_glue_release_rx_chn(struct k3_udma_glue_rx_channel *rx_chn)
> rx_chn->psil_paired = false;
> }
>
> - for (i = 0; i < rx_chn->flow_num; i++)
> - k3_udma_glue_release_rx_flow(rx_chn, i);
> + if (rx_chn->flows)
> + for (i = 0; i < rx_chn->flow_num; i++)
> + k3_udma_glue_release_rx_flow(rx_chn, i);
>
> if (xudma_rflow_is_gp(rx_chn->common.udmax, rx_chn->flow_id_base))
> xudma_free_gp_rflow_range(rx_chn->common.udmax,
> --
> 2.43.0
>
© 2016 - 2026 Red Hat, Inc.