[PATCH] fpga: dfl: Fix NULL pointer dereference in dfl_fpga_feature_devs_enumerate()

Yang Zi posted 1 patch 1 month ago
drivers/fpga/dfl.c | 2 ++
1 file changed, 2 insertions(+)
[PATCH] fpga: dfl: Fix NULL pointer dereference in dfl_fpga_feature_devs_enumerate()
Posted by Yang Zi 1 month ago
The build_info struct (binfo) is zeroed by devm_kzalloc(), but its
sub_features list head is not initialized there; INIT_LIST_HEAD() is only
called later inside parse_feature_fiu().  If parsing ends without ever
reaching parse_feature_fiu() (for example, when every feature header in
the list is an unsupported type), binfo->sub_features is still all-zero
instead of a valid empty list head.

build_info_free() then runs list_for_each_entry_safe() over that list,
which reads head->next == NULL and dereferences a NULL pointer.

KASAN report:

    BUG: KASAN: null-ptr-deref in build_info_free drivers/fpga/dfl.c:950 [inline]
    BUG: KASAN: null-ptr-deref in dfl_fpga_feature_devs_enumerate+0x59ba/0x60d0 drivers/fpga/dfl.c:1611
    Read of size 8 at addr 0000000000000000 by task syz.0.2/1096

Initialize binfo->sub_features right after allocating binfo so that
build_info_free() and the other sub_features consumers always see a valid
list head.

Signed-off-by: Yang Zi <2959243019@qq.com>
---
 drivers/fpga/dfl.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/fpga/dfl.c b/drivers/fpga/dfl.c
index 4c63c7c8579b..6377304e4447 100644
--- a/drivers/fpga/dfl.c
+++ b/drivers/fpga/dfl.c
@@ -1589,6 +1589,8 @@ dfl_fpga_feature_devs_enumerate(struct dfl_fpga_enum_info *info)
         goto unregister_region_exit;
     }
 
+    INIT_LIST_HEAD(&binfo->sub_features);
+
     binfo->type = DFL_ID_MAX;
     binfo->dev = info->dev;
     binfo->cdev = cdev;


Re: [PATCH] fpga: dfl: Fix NULL pointer dereference in dfl_fpga_feature_devs_enumerate()
Posted by Xu Yilun 2 weeks, 4 days ago
On Tue, Aug 25, 2026 at 05:08:42PM +0800, Yang Zi wrote:
> The build_info struct (binfo) is zeroed by devm_kzalloc(), but its
> sub_features list head is not initialized there; INIT_LIST_HEAD() is only
> called later inside parse_feature_fiu().  If parsing ends without ever
> reaching parse_feature_fiu() (for example, when every feature header in
> the list is an unsupported type), binfo->sub_features is still all-zero
> instead of a valid empty list head.
> 
> build_info_free() then runs list_for_each_entry_safe() over that list,
> which reads head->next == NULL and dereferences a NULL pointer.
> 
> KASAN report:
> 
>     BUG: KASAN: null-ptr-deref in build_info_free drivers/fpga/dfl.c:950 [inline]
>     BUG: KASAN: null-ptr-deref in dfl_fpga_feature_devs_enumerate+0x59ba/0x60d0 drivers/fpga/dfl.c:1611
>     Read of size 8 at addr 0000000000000000 by task syz.0.2/1096
> 
> Initialize binfo->sub_features right after allocating binfo so that
> build_info_free() and the other sub_features consumers always see a valid
> list head.
> 
> Signed-off-by: Yang Zi <2959243019@qq.com>
> ---
>  drivers/fpga/dfl.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/fpga/dfl.c b/drivers/fpga/dfl.c
> index 4c63c7c8579b..6377304e4447 100644
> --- a/drivers/fpga/dfl.c
> +++ b/drivers/fpga/dfl.c
> @@ -1589,6 +1589,8 @@ dfl_fpga_feature_devs_enumerate(struct dfl_fpga_enum_info *info)
>          goto unregister_region_exit;
>      }
>  
> +    INIT_LIST_HEAD(&binfo->sub_features);
> +

You patch format is broken, I can't apply.

>      binfo->type = DFL_ID_MAX;
>      binfo->dev = info->dev;
>      binfo->cdev = cdev;
> 
> 
>