Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH] RDMA/mlx5: Fix NULL deref in del_sa_roce_rule() on allocation failure
@ 2026-10-02 11:03 lirongqing
  2026-10-02 11:14 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: lirongqing @ 2026-10-02 11:03 UTC (permalink / raw)
  To: Leon Romanovsky, Jason Gunthorpe, linux-rdma; +Cc: Li RongQing

From: Li RongQing <lirongqing@baidu.com>

get_macsec_device() allocates and links a new mlx5_macsec_device when
the macdev has no existing entry, and returns NULL when that allocation
fails.  del_sa_roce_rule() only flagged the NULL case with WARN_ON() and
kept dereferencing macsec_device, so a MACsec SA delete event for a
macdev that was never set up by the RoCE GID path would dereference NULL
under memory pressure.

Return after the warning so the SA delete event is dropped instead of
oopsing.

Fixes: 58dbd6428a68 ("RDMA/mlx5: Handles RoCE MACsec steering rules addition and deletion")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
---
 drivers/infiniband/hw/mlx5/macsec.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx5/macsec.c b/drivers/infiniband/hw/mlx5/macsec.c
index 4732be5..37394ea 100644
--- a/drivers/infiniband/hw/mlx5/macsec.c
+++ b/drivers/infiniband/hw/mlx5/macsec.c
@@ -119,7 +119,8 @@ static void del_sa_roce_rule(struct list_head *macsec_devices_list,
 	struct mlx5_macsec_device *macsec_device;
 
 	macsec_device = get_macsec_device(data->macdev, macsec_devices_list);
-	WARN_ON(!macsec_device);
+	if (WARN_ON(!macsec_device))
+		return;
 
 	mlx5_macsec_del_roce_sa_rules(data->fs_id, data->macsec_fs,
 				      &macsec_device->tx_rules_list,
-- 
2.9.4


^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-02 11:14 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02 11:03 [PATCH] RDMA/mlx5: Fix NULL deref in del_sa_roce_rule() on allocation failure lirongqing
2026-10-02 11:14 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox