Re: [PATCH v3] RDMA/nldev: Fix NULL deref in dumps of objects abandoned by DRIVER_FAILURE

From: Leon Romanovsky

Date: Tue Sep 29 2026 - 14:22:44 EST



On Wed, 23 Sep 2026 21:12:39 +0800, Yili Zhang wrote:
> fill_res_cq_entry() dereferences
> cq->uobject->uevent.uobject.context->res.id unconditionally for user
> resources.
>
> This is normally safe by ordering: destroy_hw() removes the resource
> from the restrack before uverbs_destroy_uobject() clears ->context,
> and the XA_ZERO_ENTRY marker set by rdma_restrack_begin_del() hides
> the entry from concurrent netlink dumps.
>
> [...]

Applied, thanks!

[1/1] RDMA/nldev: Fix NULL deref in dumps of objects abandoned by DRIVER_FAILURE
https://git.kernel.org/rdma/rdma/c/9f4c322be27bf6

Best regards,
--
Leon Romanovsky <leon@xxxxxxxxxx>