drivers/fpga/dfl.c | 2 ++ 1 file changed, 2 insertions(+)
The build_info struct (binfo) is zeroed by devm_kzalloc(), but its
sub_features list head is not initialized there; INIT_LIST_HEAD() is only
called later inside parse_feature_fiu(). If parsing ends without ever
reaching parse_feature_fiu() (for example, when every feature header in
the list is an unsupported type), binfo->sub_features is still all-zero
instead of a valid empty list head.
build_info_free() then runs list_for_each_entry_safe() over that list,
which reads head->next == NULL and dereferences a NULL pointer.
KASAN report:
BUG: KASAN: null-ptr-deref in build_info_free drivers/fpga/dfl.c:950 [inline]
BUG: KASAN: null-ptr-deref in dfl_fpga_feature_devs_enumerate+0x59ba/0x60d0 drivers/fpga/dfl.c:1611
Read of size 8 at addr 0000000000000000 by task syz.0.2/1096
Initialize binfo->sub_features right after allocating binfo so that
build_info_free() and the other sub_features consumers always see a valid
list head.
Signed-off-by: Yang Zi <2959243019@qq.com>
---
drivers/fpga/dfl.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/fpga/dfl.c b/drivers/fpga/dfl.c
index 4c63c7c8579b..6377304e4447 100644
--- a/drivers/fpga/dfl.c
+++ b/drivers/fpga/dfl.c
@@ -1589,6 +1589,8 @@ dfl_fpga_feature_devs_enumerate(struct dfl_fpga_enum_info *info)
goto unregister_region_exit;
}
+ INIT_LIST_HEAD(&binfo->sub_features);
+
binfo->type = DFL_ID_MAX;
binfo->dev = info->dev;
binfo->cdev = cdev;
On Tue, Aug 25, 2026 at 05:08:42PM +0800, Yang Zi wrote: > The build_info struct (binfo) is zeroed by devm_kzalloc(), but its > sub_features list head is not initialized there; INIT_LIST_HEAD() is only > called later inside parse_feature_fiu(). If parsing ends without ever > reaching parse_feature_fiu() (for example, when every feature header in > the list is an unsupported type), binfo->sub_features is still all-zero > instead of a valid empty list head. > > build_info_free() then runs list_for_each_entry_safe() over that list, > which reads head->next == NULL and dereferences a NULL pointer. > > KASAN report: > > BUG: KASAN: null-ptr-deref in build_info_free drivers/fpga/dfl.c:950 [inline] > BUG: KASAN: null-ptr-deref in dfl_fpga_feature_devs_enumerate+0x59ba/0x60d0 drivers/fpga/dfl.c:1611 > Read of size 8 at addr 0000000000000000 by task syz.0.2/1096 > > Initialize binfo->sub_features right after allocating binfo so that > build_info_free() and the other sub_features consumers always see a valid > list head. > > Signed-off-by: Yang Zi <2959243019@qq.com> > --- > drivers/fpga/dfl.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/fpga/dfl.c b/drivers/fpga/dfl.c > index 4c63c7c8579b..6377304e4447 100644 > --- a/drivers/fpga/dfl.c > +++ b/drivers/fpga/dfl.c > @@ -1589,6 +1589,8 @@ dfl_fpga_feature_devs_enumerate(struct dfl_fpga_enum_info *info) > goto unregister_region_exit; > } > > + INIT_LIST_HEAD(&binfo->sub_features); > + You patch format is broken, I can't apply. > binfo->type = DFL_ID_MAX; > binfo->dev = info->dev; > binfo->cdev = cdev; > > >
© 2016 - 2026 Red Hat, Inc.