Re: [PATCH v3] RDMA/nldev: Fix NULL deref in dumps of objects abandoned by DRIVER_FAILURE
From: Leon Romanovsky
Date: Tue Sep 29 2026 - 14:22:44 EST
On Wed, 23 Sep 2026 21:12:39 +0800, Yili Zhang wrote:
> fill_res_cq_entry() dereferences
> cq->uobject->uevent.uobject.context->res.id unconditionally for user
> resources.
>
> This is normally safe by ordering: destroy_hw() removes the resource
> from the restrack before uverbs_destroy_uobject() clears ->context,
> and the XA_ZERO_ENTRY marker set by rdma_restrack_begin_del() hides
> the entry from concurrent netlink dumps.
>
> [...]
Applied, thanks!
[1/1] RDMA/nldev: Fix NULL deref in dumps of objects abandoned by DRIVER_FAILURE
https://git.kernel.org/rdma/rdma/c/9f4c322be27bf6
Best regards,
--
Leon Romanovsky <leon@xxxxxxxxxx>