From: Bhargava Marreddy <bhargava.marreddy@broadcom.com>
To: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, andrew+netdev@lunn.ch, horms@kernel.org
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
michael.chan@broadcom.com, pavan.chebbi@broadcom.com,
vsrama-krishna.nemani@broadcom.com, vikas.gupta@broadcom.com,
Bhargava Marreddy <bhargava.marreddy@broadcom.com>,
Dharmender Garg <dharmender.garg@broadcom.com>,
Rajashekar Hudumula <rajashekar.hudumula@broadcom.com>,
Ramakrishna Koduri <ramakrishna.koduri@broadcom.com>
Subject: [PATCH net 1/4] bnge: fix NULL deref in bnge_alloc_core() on failure
Date: Mon, 5 Oct 2026 17:47:01 +0530 [thread overview]
Message-ID: <20261005121704.227866-2-bhargava.marreddy@broadcom.com> (raw)
In-Reply-To: <20261005121704.227866-1-bhargava.marreddy@broadcom.com>
bnge_alloc_core() previously jumped to a single error label that called
bnge_free_core() to unwind. However, bnge_free_core() assumes a fully
initialized state and dereferences rx/tx ring arrays unconditionally.
If ring allocations fail early, this causes a near-NULL dereference.
Introduce a standard goto ladder to unwind only the resources that were
successfully allocated, preventing NULL dereferences.
Fixes: 0259379037ca ("bng_en: Add initial support for RX and TX rings")
Signed-off-by: Bhargava Marreddy <bhargava.marreddy@broadcom.com>
Reviewed-by: Dharmender Garg <dharmender.garg@broadcom.com>
Reviewed-by: Rajashekar Hudumula <rajashekar.hudumula@broadcom.com>
Reviewed-by: Ramakrishna Koduri <ramakrishna.koduri@broadcom.com>
---
.../net/ethernet/broadcom/bnge/bnge_netdev.c | 46 ++++++++++++++-----
1 file changed, 34 insertions(+), 12 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/bnge/bnge_netdev.c b/drivers/net/ethernet/broadcom/bnge/bnge_netdev.c
index a4288f0258f8..bf101eded3bf 100644
--- a/drivers/net/ethernet/broadcom/bnge/bnge_netdev.c
+++ b/drivers/net/ethernet/broadcom/bnge/bnge_netdev.c
@@ -1243,7 +1243,7 @@ static int bnge_alloc_core(struct bnge_net *bn)
bn->rx_ring = kzalloc_objs(struct bnge_rx_ring_info, bd->rx_nr_rings);
if (!bn->rx_ring)
- goto err_free_core;
+ goto err_free_bnapi;
for (i = 0; i < bd->rx_nr_rings; i++) {
struct bnge_rx_ring_info *rxr = &bn->rx_ring[i];
@@ -1258,12 +1258,12 @@ static int bnge_alloc_core(struct bnge_net *bn)
bn->tx_ring = kzalloc_objs(struct bnge_tx_ring_info, bd->tx_nr_rings);
if (!bn->tx_ring)
- goto err_free_core;
+ goto err_free_rx_ring;
bn->tx_ring_map = kcalloc(bd->tx_nr_rings, sizeof(u16),
GFP_KERNEL);
if (!bn->tx_ring_map)
- goto err_free_core;
+ goto err_free_tx_ring;
if (bd->flags & BNGE_EN_SHARED_CHNL)
j = 0;
@@ -1289,42 +1289,64 @@ static int bnge_alloc_core(struct bnge_net *bn)
rc = bnge_alloc_ring_stats(bn);
if (rc)
- goto err_free_core;
+ goto err_free_tx_ring_map;
bnge_init_stats(bn);
rc = bnge_alloc_vnics(bn);
if (rc)
- goto err_free_core;
+ goto err_free_ring_stats;
rc = bnge_alloc_nq_arrays(bn);
if (rc)
- goto err_free_core;
+ goto err_free_vnics;
bnge_init_ring_struct(bn);
rc = bnge_alloc_rx_rings(bn);
if (rc)
- goto err_free_core;
+ goto err_free_nq_arrays;
rc = bnge_alloc_tx_rings(bn);
if (rc)
- goto err_free_core;
+ goto err_free_rx_rings;
rc = bnge_alloc_nq_tree(bn);
if (rc)
- goto err_free_core;
+ goto err_free_tx_rings;
bn->vnic_info[BNGE_VNIC_DEFAULT].flags |= BNGE_VNIC_RSS_FLAG |
BNGE_VNIC_MCAST_FLAG |
BNGE_VNIC_UCAST_FLAG;
rc = bnge_alloc_vnic_attributes(bn);
if (rc)
- goto err_free_core;
+ goto err_free_nq_tree;
return 0;
-err_free_core:
- bnge_free_core(bn);
+err_free_nq_tree:
+ bnge_free_nq_tree(bn);
+err_free_tx_rings:
+ bnge_free_tx_rings(bn);
+err_free_rx_rings:
+ bnge_free_rx_rings(bn);
+err_free_nq_arrays:
+ bnge_free_nq_arrays(bn);
+err_free_vnics:
+ bnge_free_vnics(bn);
+err_free_ring_stats:
+ bnge_free_ring_stats(bn);
+err_free_tx_ring_map:
+ kfree(bn->tx_ring_map);
+ bn->tx_ring_map = NULL;
+err_free_tx_ring:
+ kfree(bn->tx_ring);
+ bn->tx_ring = NULL;
+err_free_rx_ring:
+ kfree(bn->rx_ring);
+ bn->rx_ring = NULL;
+err_free_bnapi:
+ kfree(bn->bnapi);
+ bn->bnapi = NULL;
return rc;
}
--
2.47.3
next prev parent reply other threads:[~2026-10-05 12:18 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 12:17 [PATCH net 0/4] bnge: Fix error-path and IRQ setup bugs in probe/open Bhargava Marreddy
2026-10-05 12:17 ` Bhargava Marreddy [this message]
2026-10-05 12:17 ` [PATCH net 2/4] bnge: require NQ vectors beyond aux reservation Bhargava Marreddy
2026-10-05 12:17 ` [PATCH net 3/4] bnge: do not fail open if IRQ affinity hint fails Bhargava Marreddy
2026-10-05 12:17 ` [PATCH net 4/4] bnge: clear bd->netdev on allocation failure Bhargava Marreddy
2026-10-05 12:23 ` [PATCH net 0/4] bnge: Fix error-path and IRQ setup bugs in probe/open netdev-bot+sinfo
2026-10-05 12:42 ` Bhargava Chenna Marreddy
2026-10-05 12:57 ` Przemek Kitszel
2026-10-07 1:40 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005121704.227866-2-bhargava.marreddy@broadcom.com \
--to=bhargava.marreddy@broadcom.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=dharmender.garg@broadcom.com \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=michael.chan@broadcom.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pavan.chebbi@broadcom.com \
--cc=rajashekar.hudumula@broadcom.com \
--cc=ramakrishna.koduri@broadcom.com \
--cc=vikas.gupta@broadcom.com \
--cc=vsrama-krishna.nemani@broadcom.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.