Re: [PATCH] fpga: dfl: Fix NULL pointer dereference in dfl_fpga_feature_devs_enumerate()
From: Xu Yilun
Date: Wed Sep 09 2026 - 03:52:10 EST
On Tue, Aug 25, 2026 at 05:08:42PM +0800, Yang Zi wrote:
> The build_info struct (binfo) is zeroed by devm_kzalloc(), but its
> sub_features list head is not initialized there; INIT_LIST_HEAD() is only
> called later inside parse_feature_fiu(). If parsing ends without ever
> reaching parse_feature_fiu() (for example, when every feature header in
> the list is an unsupported type), binfo->sub_features is still all-zero
> instead of a valid empty list head.
>
> build_info_free() then runs list_for_each_entry_safe() over that list,
> which reads head->next == NULL and dereferences a NULL pointer.
>
> KASAN report:
>
> BUG: KASAN: null-ptr-deref in build_info_free drivers/fpga/dfl.c:950 [inline]
> BUG: KASAN: null-ptr-deref in dfl_fpga_feature_devs_enumerate+0x59ba/0x60d0 drivers/fpga/dfl.c:1611
> Read of size 8 at addr 0000000000000000 by task syz.0.2/1096
>
> Initialize binfo->sub_features right after allocating binfo so that
> build_info_free() and the other sub_features consumers always see a valid
> list head.
>
> Signed-off-by: Yang Zi <2959243019@xxxxxx>
> ---
> drivers/fpga/dfl.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/fpga/dfl.c b/drivers/fpga/dfl.c
> index 4c63c7c8579b..6377304e4447 100644
> --- a/drivers/fpga/dfl.c
> +++ b/drivers/fpga/dfl.c
> @@ -1589,6 +1589,8 @@ dfl_fpga_feature_devs_enumerate(struct dfl_fpga_enum_info *info)
> goto unregister_region_exit;
> }
>
> + INIT_LIST_HEAD(&binfo->sub_features);
> +
You patch format is broken, I can't apply.
> binfo->type = DFL_ID_MAX;
> binfo->dev = info->dev;
> binfo->cdev = cdev;
>
>
>