Re: [PATCH] staging: greybus: bootrom: fix null pointer dereference in get_firmware
From: Johan Hovold
Date: Mon Oct 05 2026 - 04:23:01 EST
On Mon, Oct 05, 2026 at 01:34:54AM -0500, Marinela Tatiana Selseth wrote:
> Automated static analysis via Coccinelle uncovered a potential null
> pointer dereference and uninitialized stack pointer vulnerability
> inside gb_bootrom_get_firmware().
Please check the archives to see why coccinelle is wrong.
> The routine evaluates whether a firmware transmission sequence is
> complete at its trailing 'queue_work:' label by checking if the
> transfer bounds match 'fw->size'.
> When this label is reached the 'fw' can be uninitialized or NULL.
> Both scenarios expose the kernel to critical memory faults or null
> pointer panics.
>
> Fix these dual vulnerability paths by initializing the 'fw' pointer
> to NULL at its top-level definition block and introducing an
> explicit short-circuit guard condition to safely gate the
> trailing size evaluation.
>
> Assisted-by: Gemini
Also, LLM assisted patches are rejected for staging (again, see the
archives).
> Signed-off-by: Marinela Tatiana Selseth <marinela.selseth@xxxxxxxxxxxxxxxxxx>
Johan