From: Oliver Neukum <oliver@neukum.org>
To: linux-usb-devel@lists.sourceforge.net
Cc: "Jesper Juhl" <jesper.juhl@gmail.com>,
"Satyam Sharma" <satyam.sharma@gmail.com>,
Greg Kroah-Hartman <greg@kroah.com>,
netdev@vger.kernel.org,
Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
Petko Manolov <petkan@users.sourceforge.net>
Subject: Re: [linux-usb-devel] [PATCH] USB Pegasus driver - avoid a potential NULL pointer dereference.
Date: Sun, 29 Jul 2007 10:49:26 +0200 [thread overview]
Message-ID: <200707291049.26619.oliver@neukum.org> (raw)
In-Reply-To: <9a8748490707281655u66e50bbfqba58687b579a85fe@mail.gmail.com>
Am Sonntag 29 Juli 2007 schrieb Jesper Juhl:
> On 29/07/07, Satyam Sharma <satyam.sharma@gmail.com> wrote:
> > Hi,
> >
> > On 7/29/07, Jesper Juhl <jesper.juhl@gmail.com> wrote:
> > > Hello,
> > >
> > > This patch makes sure we don't dereference a NULL pointer in
> > > drivers/net/usb/pegasus.c::write_bulk_callback() in the initial
> > > struct net_device *net = pegasus->net; assignment.
> > > The existing code checks if 'pegasus' is NULL and bails out if
> > > it is, so we better not touch that pointer until after that check.
> > > [...]
> > > diff --git a/drivers/net/usb/pegasus.c b/drivers/net/usb/pegasus.c
> > > index a05fd97..04cba6b 100644
> > > --- a/drivers/net/usb/pegasus.c
> > > +++ b/drivers/net/usb/pegasus.c
> > > @@ -768,11 +768,13 @@ done:
> > > static void write_bulk_callback(struct urb *urb)
> > > {
> > > pegasus_t *pegasus = urb->context;
> > > - struct net_device *net = pegasus->net;
> > > + struct net_device *net;
> > >
> > > if (!pegasus)
> > > return;
> > >
> > > + net = pegasus->net;
> > > +
> > > if (!netif_device_present(net) || !netif_running(net))
> > > return;
> >
> > Is it really possible that we're called into this function with
> > urb->context == NULL? If not, I'd suggest let's just get rid of
> > the check itself, instead.
> >
> I'm not sure. I am not very familiar with this code. I just figured
> that moving the assignment is potentially a little safer and it is
> certainly no worse than the current code, so that's a safe and
> potentially benneficial change. Removing the check may be safe but I'm
> not certain enough to make that call...
pegasus == NULL there would be a kernel bug. Silently ignoring
it, like the code now wants to do is bad. As the oops has never been
reported, I figure turning it into an explicit debugging test is overkill,
so removal seems to be the best option.
Regards
Oliver
next prev parent reply other threads:[~2007-07-29 8:47 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-07-28 22:19 [PATCH] USB Pegasus driver - avoid a potential NULL pointer dereference Jesper Juhl
2007-07-28 22:19 ` Jesper Juhl
2007-07-28 23:37 ` Satyam Sharma
2007-07-28 23:37 ` Satyam Sharma
2007-07-28 23:55 ` Jesper Juhl
2007-07-28 23:55 ` Jesper Juhl
2007-07-29 8:49 ` Oliver Neukum [this message]
2007-07-29 18:18 ` [linux-usb-devel] " Satyam Sharma
2007-07-29 18:18 ` Satyam Sharma
2007-07-30 8:05 ` [linux-usb-devel] " Petko Manolov
2007-07-30 8:05 ` Petko Manolov
2007-07-30 8:54 ` [linux-usb-devel] " Satyam Sharma
2007-07-30 8:54 ` Satyam Sharma
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200707291049.26619.oliver@neukum.org \
--to=oliver@neukum.org \
--cc=greg@kroah.com \
--cc=jesper.juhl@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb-devel@lists.sourceforge.net \
--cc=netdev@vger.kernel.org \
--cc=petkan@users.sourceforge.net \
--cc=satyam.sharma@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.