From: merez@codeaurora.org
To: Colin King <colin.king@canonical.com>
Cc: Kalle Valo <kvalo@codeaurora.org>,
linux-wireless@vger.kernel.org, wil6210@qti.qualcomm.com,
netdev@vger.kernel.org, kernel-janitors@vger.kernel.org,
linux-kernel@vger.kernel.org,
linux-wireless-owner@vger.kernel.org
Subject: Re: [PATCH][next] wil6210: fix potential null dereference of ndev before null check
Date: Wed, 28 Mar 2018 17:46:44 +0000 [thread overview]
Message-ID: <49ef31bc36217349a4801dc2eba4735c@codeaurora.org> (raw)
In-Reply-To: <20180328174027.31551-1-colin.king@canonical.com>
On 2018-03-28 20:40, Colin King wrote:
> From: Colin Ian King <colin.king@canonical.com>
>
> The pointer ndev is being dereferenced before it is being null checked,
> hence there is a potential null pointer deference. Fix this by only
> dereferencing ndev after it has been null checked
>
> Detected by CoverityScan, CID#1467010 ("Dereference before null check")
>
> Fixes: e00243fab84b ("wil6210: infrastructure for multiple virtual
> interfaces")
> Signed-off-by: Colin Ian King <colin.king@canonical.com>
> ---
> drivers/net/wireless/ath/wil6210/main.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/wireless/ath/wil6210/main.c
> b/drivers/net/wireless/ath/wil6210/main.c
> index a4b413e8d55a..82aec6b06d09 100644
> --- a/drivers/net/wireless/ath/wil6210/main.c
> +++ b/drivers/net/wireless/ath/wil6210/main.c
> @@ -391,7 +391,7 @@ static void wil_fw_error_worker(struct work_struct
> *work)
> struct wil6210_priv *wil = container_of(work, struct wil6210_priv,
> fw_error_worker);
> struct net_device *ndev = wil->main_ndev;
> - struct wireless_dev *wdev = ndev->ieee80211_ptr;
> + struct wireless_dev *wdev;
>
> wil_dbg_misc(wil, "fw error worker\n");
>
> @@ -399,6 +399,7 @@ static void wil_fw_error_worker(struct work_struct
> *work)
> wil_info(wil, "No recovery - interface is down\n");
> return;
> }
> + wdev = ndev->ieee80211_ptr;
>
> /* increment @recovery_count if less then WIL6210_FW_RECOVERY_TO
> * passed since last recovery attempt
Reviewed-by: Maya Erez <merez@codeaurora.org>
--
Maya Erez
Qualcomm Israel, Inc. on behalf of Qualcomm Innovation Center, Inc.
The Qualcomm Innovation Center, Inc. is a member of Code Aurora Forum, a
Linux Foundation Collaborative Project
WARNING: multiple messages have this Message-ID (diff)
From: merez@codeaurora.org
To: Colin King <colin.king@canonical.com>
Cc: Kalle Valo <kvalo@codeaurora.org>,
linux-wireless@vger.kernel.org, wil6210@qti.qualcomm.com,
netdev@vger.kernel.org, kernel-janitors@vger.kernel.org,
linux-kernel@vger.kernel.org,
linux-wireless-owner@vger.kernel.org
Subject: Re: [PATCH][next] wil6210: fix potential null dereference of ndev before null check
Date: Wed, 28 Mar 2018 20:46:44 +0300 [thread overview]
Message-ID: <49ef31bc36217349a4801dc2eba4735c@codeaurora.org> (raw)
In-Reply-To: <20180328174027.31551-1-colin.king@canonical.com>
On 2018-03-28 20:40, Colin King wrote:
> From: Colin Ian King <colin.king@canonical.com>
>
> The pointer ndev is being dereferenced before it is being null checked,
> hence there is a potential null pointer deference. Fix this by only
> dereferencing ndev after it has been null checked
>
> Detected by CoverityScan, CID#1467010 ("Dereference before null check")
>
> Fixes: e00243fab84b ("wil6210: infrastructure for multiple virtual
> interfaces")
> Signed-off-by: Colin Ian King <colin.king@canonical.com>
> ---
> drivers/net/wireless/ath/wil6210/main.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/wireless/ath/wil6210/main.c
> b/drivers/net/wireless/ath/wil6210/main.c
> index a4b413e8d55a..82aec6b06d09 100644
> --- a/drivers/net/wireless/ath/wil6210/main.c
> +++ b/drivers/net/wireless/ath/wil6210/main.c
> @@ -391,7 +391,7 @@ static void wil_fw_error_worker(struct work_struct
> *work)
> struct wil6210_priv *wil = container_of(work, struct wil6210_priv,
> fw_error_worker);
> struct net_device *ndev = wil->main_ndev;
> - struct wireless_dev *wdev = ndev->ieee80211_ptr;
> + struct wireless_dev *wdev;
>
> wil_dbg_misc(wil, "fw error worker\n");
>
> @@ -399,6 +399,7 @@ static void wil_fw_error_worker(struct work_struct
> *work)
> wil_info(wil, "No recovery - interface is down\n");
> return;
> }
> + wdev = ndev->ieee80211_ptr;
>
> /* increment @recovery_count if less then WIL6210_FW_RECOVERY_TO
> * passed since last recovery attempt
Reviewed-by: Maya Erez <merez@codeaurora.org>
--
Maya Erez
Qualcomm Israel, Inc. on behalf of Qualcomm Innovation Center, Inc.
The Qualcomm Innovation Center, Inc. is a member of Code Aurora Forum, a
Linux Foundation Collaborative Project
next prev parent reply other threads:[~2018-03-28 17:46 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-03-28 17:40 [PATCH][next] wil6210: fix potential null dereference of ndev before null check Colin King
2018-03-28 17:40 ` Colin King
2018-03-28 17:46 ` merez [this message]
2018-03-28 17:46 ` merez
2018-03-29 4:53 ` Kalle Valo
2018-03-29 4:53 ` Kalle Valo
2018-04-10 14:30 ` [next] " Kalle Valo
2018-04-10 14:30 ` Kalle Valo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=49ef31bc36217349a4801dc2eba4735c@codeaurora.org \
--to=merez@codeaurora.org \
--cc=colin.king@canonical.com \
--cc=kernel-janitors@vger.kernel.org \
--cc=kvalo@codeaurora.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless-owner@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=wil6210@qti.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.