Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Sudeep Holla <sudeep.holla@arm.com>
To: linux-arm-kernel@lists.infradead.org,
	Sudeep Holla <sudeep.holla@arm.com>
Cc: Viresh Kumar <viresh.kumar@linaro.org>,
	Cristian Marussi <cristian.marussi@arm.com>
Subject: Re: [PATCH] firmware: arm_scmi: Fix NULL pointer dereference in mailbox_chan_free
Date: Mon, 14 Sep 2020 07:34:23 +0100	[thread overview]
Message-ID: <160006520686.28306.2580641037987580617.b4-ty@arm.com> (raw)
In-Reply-To: <20200908112611.31515-1-sudeep.holla@arm.com>

On Tue, 8 Sep 2020 12:26:11 +0100, Sudeep Holla wrote:
> scmi_mailbox is obtained from cinfo->transport_info and the first
> call to mailbox_chan_free frees the channel and sets cinfo->transport_info
> to NULL. Care is taken to check for non NULL smbox->chan but smbox can
> itself be NULL. Fix it by checking for it without which, kernel crashes
> with below NULL pointer dereference and eventually kernel panic.
> 
>    Unable to handle kernel NULL pointer dereference at
>    		virtual address 0000000000000038
>    Modules linked in: scmi_module(-)
>    Hardware name: ARM LTD ARM Juno Development Platform/ARM Juno
>    		Development Platform, BIOS EDK II Sep  2 2020
>    pstate: 80000005 (Nzcv daif -PAN -UAO BTYPE=--)
>    pc : mailbox_chan_free+0x2c/0x70 [scmi_module]
>    lr : idr_for_each+0x6c/0xf8
>    Call trace:
>     mailbox_chan_free+0x2c/0x70 [scmi_module]
>     idr_for_each+0x6c/0xf8
>     scmi_remove+0xa8/0xf0 [scmi_module]
>     platform_drv_remove+0x34/0x58
>     device_release_driver_internal+0x118/0x1f0
>     driver_detach+0x58/0xe8
>     bus_remove_driver+0x64/0xe0
>     driver_unregister+0x38/0x68
>     platform_driver_unregister+0x1c/0x28
>     scmi_driver_exit+0x38/0x44 [scmi_module]
>    ---[ end trace 17bde19f50436de9 ]---
>    Kernel panic - not syncing: Fatal exception
>    SMP: stopping secondary CPUs
>    Kernel Offset: 0x1d0000 from 0xffff800010000000
>    PHYS_OFFSET: 0x80000000
>    CPU features: 0x0240022,25806004
>    Memory Limit: none
>    ---[ end Kernel panic - not syncing: Fatal exception ]---


Applied to sudeep.holla/linux (for-next/scmi), thanks!

[1/1] firmware: arm_scmi: Fix NULL pointer dereference in mailbox_chan_free
      https://git.kernel.org/sudeep.holla/c/6ed6c55823

--

Regards,
Sudeep


_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel

      parent reply	other threads:[~2020-09-14  6:35 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-09-08 11:26 [PATCH] firmware: arm_scmi: Fix NULL pointer dereference in mailbox_chan_free Sudeep Holla
2020-09-08 15:24 ` Cristian Marussi
2020-09-09  3:47 ` Viresh Kumar
2020-09-14  6:34 ` Sudeep Holla [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=160006520686.28306.2580641037987580617.b4-ty@arm.com \
    --to=sudeep.holla@arm.com \
    --cc=cristian.marussi@arm.com \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=viresh.kumar@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox