* [PATCH] RDMA/mlx5: Fix NULL deref in del_sa_roce_rule() on allocation failure
@ 2026-10-02 11:03 lirongqing
2026-10-02 11:14 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: lirongqing @ 2026-10-02 11:03 UTC (permalink / raw)
To: Leon Romanovsky, Jason Gunthorpe, linux-rdma; +Cc: Li RongQing
From: Li RongQing <lirongqing@baidu.com>
get_macsec_device() allocates and links a new mlx5_macsec_device when
the macdev has no existing entry, and returns NULL when that allocation
fails. del_sa_roce_rule() only flagged the NULL case with WARN_ON() and
kept dereferencing macsec_device, so a MACsec SA delete event for a
macdev that was never set up by the RoCE GID path would dereference NULL
under memory pressure.
Return after the warning so the SA delete event is dropped instead of
oopsing.
Fixes: 58dbd6428a68 ("RDMA/mlx5: Handles RoCE MACsec steering rules addition and deletion")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
---
drivers/infiniband/hw/mlx5/macsec.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/mlx5/macsec.c b/drivers/infiniband/hw/mlx5/macsec.c
index 4732be5..37394ea 100644
--- a/drivers/infiniband/hw/mlx5/macsec.c
+++ b/drivers/infiniband/hw/mlx5/macsec.c
@@ -119,7 +119,8 @@ static void del_sa_roce_rule(struct list_head *macsec_devices_list,
struct mlx5_macsec_device *macsec_device;
macsec_device = get_macsec_device(data->macdev, macsec_devices_list);
- WARN_ON(!macsec_device);
+ if (WARN_ON(!macsec_device))
+ return;
mlx5_macsec_del_roce_sa_rules(data->fs_id, data->macsec_fs,
&macsec_device->tx_rules_list,
--
2.9.4
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] RDMA/mlx5: Fix NULL deref in del_sa_roce_rule() on allocation failure
2026-10-02 11:03 [PATCH] RDMA/mlx5: Fix NULL deref in del_sa_roce_rule() on allocation failure lirongqing
@ 2026-10-02 11:14 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-10-02 11:14 UTC (permalink / raw)
To: lirongqing; +Cc: linux-rdma
> From: Li RongQing <lirongqing@baidu.com>
>
> get_macsec_device() allocates and links a new mlx5_macsec_device when
> the macdev has no existing entry, and returns NULL when that allocation
> fails. del_sa_roce_rule() only flagged the NULL case with WARN_ON() and
> kept dereferencing macsec_device, so a MACsec SA delete event for a
> macdev that was never set up by the RoCE GID path would dereference NULL
> under memory pressure.
>
> Return after the warning so the SA delete event is dropped instead of
> oopsing.
>
> Fixes: 58dbd6428a68 ("RDMA/mlx5: Handles RoCE MACsec steering rules addition and deletion")
> Signed-off-by: Li RongQing <lirongqing@baidu.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002110329.2350-1-lirongqing@baidu.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-02 11:14 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02 11:03 [PATCH] RDMA/mlx5: Fix NULL deref in del_sa_roce_rule() on allocation failure lirongqing
2026-10-02 11:14 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox