RE: [PATCH] rapidio: fix a NULL pointer derefenrece when create_workqueue fails

From: alex.bou9
Date: Mon Mar 18 2019 - 18:46:23 EST


Please correct spelling in the subject line: "dereference"

-----Original Message-----
From: Kangjie Lu <kjlu@xxxxxxx>
Sent: Thursday, March 14, 2019 2:10 AM
To: kjlu@xxxxxxx
Cc: pakki001@xxxxxxx; Matt Porter <mporter@xxxxxxxxxxxxxxxxxxx>; Alexandre
Bounine <alex.bou9@xxxxxxxxx>; linux-kernel@xxxxxxxxxxxxxxx
Subject: [PATCH] rapidio: fix a NULL pointer derefenrece when
create_workqueue fails

In case create_workqueue fails, the fix releases resources and
returns -ENOMEM to avoid NULL pointer dereference.

Signed-off-by: Kangjie Lu <kjlu@xxxxxxx>
---
drivers/rapidio/rio_cm.c | 8 ++++++++
1 file changed, 8 insertions(+)

diff --git a/drivers/rapidio/rio_cm.c b/drivers/rapidio/rio_cm.c
index cf45829585cb..b29fc258eeba 100644
--- a/drivers/rapidio/rio_cm.c
+++ b/drivers/rapidio/rio_cm.c
@@ -2147,6 +2147,14 @@ static int riocm_add_mport(struct device *dev,
mutex_init(&cm->rx_lock);
riocm_rx_fill(cm, RIOCM_RX_RING_SIZE);
cm->rx_wq = create_workqueue(DRV_NAME "/rxq");
+ if (!cm->rx_wq) {
+ riocm_error("failed to allocate IBMBOX_%d on %s",
+ cmbox, mport->name);
+ rio_release_outb_mbox(mport, cmbox);
+ kfree(cm);
+ return -ENOMEM;
+ }
+
INIT_WORK(&cm->rx_work, rio_ibmsg_handler);

cm->tx_slot = 0;
--
2.17.1