* [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation
@ 2025-04-15 12:41 Henry Martin
2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin
2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin
0 siblings, 2 replies; 7+ messages in thread
From: Henry Martin @ 2025-04-15 12:41 UTC (permalink / raw)
To: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba,
pabeni
Cc: netdev, linux-rdma, linux-kernel, bsdhenrymartin, amirtz, ayal
This patch series addresses two issues in the
mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() functions:
1. A potential NULL pointer dereference if mlx5_get_flow_namespace()
returns NULL.
2. A memory leak in the error path when ttc_type is invalid (default:
switch case).
Henry Martin (2):
net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
net/mlx5: Fix memory leak in error path of ttc creation
drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
--
2.34.1
^ permalink raw reply [flat|nested] 7+ messages in thread* [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() 2025-04-15 12:41 [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation Henry Martin @ 2025-04-15 12:41 ` Henry Martin 2025-04-15 13:45 ` Mark Bloch 2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin 1 sibling, 1 reply; 7+ messages in thread From: Henry Martin @ 2025-04-15 12:41 UTC (permalink / raw) To: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba, pabeni Cc: netdev, linux-rdma, linux-kernel, bsdhenrymartin, amirtz, ayal Add NULL check for mlx5_get_flow_namespace() returns in mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() to prevent NULL pointer dereference. Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table") Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com> --- drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c index eb3bd9c7f66e..e48afd620d7e 100644 --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c @@ -655,6 +655,11 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev, } ns = mlx5_get_flow_namespace(dev, params->ns_type); + if (!ns) { + kvfree(ttc); + return ERR_PTR(-EOPNOTSUPP); + } + groups = use_l4_type ? &inner_ttc_groups[TTC_GROUPS_USE_L4_TYPE] : &inner_ttc_groups[TTC_GROUPS_DEFAULT]; @@ -728,6 +733,11 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev, } ns = mlx5_get_flow_namespace(dev, params->ns_type); + if (!ns) { + kvfree(ttc); + return ERR_PTR(-EOPNOTSUPP); + } + groups = use_l4_type ? &ttc_groups[TTC_GROUPS_USE_L4_TYPE] : &ttc_groups[TTC_GROUPS_DEFAULT]; -- 2.34.1 ^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() 2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin @ 2025-04-15 13:45 ` Mark Bloch 2025-04-16 8:43 ` Tariq Toukan 0 siblings, 1 reply; 7+ messages in thread From: Mark Bloch @ 2025-04-15 13:45 UTC (permalink / raw) To: Henry Martin, saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba, pabeni Cc: netdev, linux-rdma, linux-kernel, amirtz, ayal On 15/04/2025 15:41, Henry Martin wrote: > Add NULL check for mlx5_get_flow_namespace() returns in > mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() to prevent > NULL pointer dereference. > > Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table") > Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com> > --- > drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 10 ++++++++++ > 1 file changed, 10 insertions(+) > > diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c > index eb3bd9c7f66e..e48afd620d7e 100644 > --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c > +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c > @@ -655,6 +655,11 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev, > } > > ns = mlx5_get_flow_namespace(dev, params->ns_type); > + if (!ns) { > + kvfree(ttc); > + return ERR_PTR(-EOPNOTSUPP); > + } > + > groups = use_l4_type ? &inner_ttc_groups[TTC_GROUPS_USE_L4_TYPE] : > &inner_ttc_groups[TTC_GROUPS_DEFAULT]; > > @@ -728,6 +733,11 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev, > } > > ns = mlx5_get_flow_namespace(dev, params->ns_type); > + if (!ns) { > + kvfree(ttc); > + return ERR_PTR(-EOPNOTSUPP); > + } > + > groups = use_l4_type ? &ttc_groups[TTC_GROUPS_USE_L4_TYPE] : > &ttc_groups[TTC_GROUPS_DEFAULT]; > Reviewed-by: Mark Bloch <mbloch@nvidia.com> Mark ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() 2025-04-15 13:45 ` Mark Bloch @ 2025-04-16 8:43 ` Tariq Toukan 0 siblings, 0 replies; 7+ messages in thread From: Tariq Toukan @ 2025-04-16 8:43 UTC (permalink / raw) To: andrew+netdev, davem, edumazet, kuba, pabeni Cc: netdev, linux-rdma, linux-kernel, amirtz, ayal, Gal Pressman, Tariq Toukan, Leon Romanovsky, Saeed Mahameed, Henry Martin, Mark Bloch On 15/04/2025 16:45, Mark Bloch wrote: > > > On 15/04/2025 15:41, Henry Martin wrote: >> Add NULL check for mlx5_get_flow_namespace() returns in >> mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() to prevent >> NULL pointer dereference. >> >> Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table") >> Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com> >> --- >> drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 10 ++++++++++ >> 1 file changed, 10 insertions(+) >> >> diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c >> index eb3bd9c7f66e..e48afd620d7e 100644 >> --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c >> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c >> @@ -655,6 +655,11 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev, >> } >> >> ns = mlx5_get_flow_namespace(dev, params->ns_type); >> + if (!ns) { >> + kvfree(ttc); >> + return ERR_PTR(-EOPNOTSUPP); >> + } >> + >> groups = use_l4_type ? &inner_ttc_groups[TTC_GROUPS_USE_L4_TYPE] : >> &inner_ttc_groups[TTC_GROUPS_DEFAULT]; >> >> @@ -728,6 +733,11 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev, >> } >> >> ns = mlx5_get_flow_namespace(dev, params->ns_type); >> + if (!ns) { >> + kvfree(ttc); >> + return ERR_PTR(-EOPNOTSUPP); >> + } >> + >> groups = use_l4_type ? &ttc_groups[TTC_GROUPS_USE_L4_TYPE] : >> &ttc_groups[TTC_GROUPS_DEFAULT]; >> > > Reviewed-by: Mark Bloch <mbloch@nvidia.com> > > Mark > netdev maintainers, Note that Mark is covering me while I'm on vacation (for the coming ~10 days). Please accordingly honor his submissions and replies for mlx5 content. In case this mail notification is not sufficient, please let us know what extra action is required. Happy Holidays, Tariq ^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation 2025-04-15 12:41 [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation Henry Martin 2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin @ 2025-04-15 12:41 ` Henry Martin 2025-04-15 13:46 ` Mark Bloch 1 sibling, 1 reply; 7+ messages in thread From: Henry Martin @ 2025-04-15 12:41 UTC (permalink / raw) To: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba, pabeni Cc: netdev, linux-rdma, linux-kernel, bsdhenrymartin, amirtz, ayal Free ttc table memory when unsupported ttc_type is passed, to avoid memory leak on the default error path in mlx5_create_inner_ttc_table() and mlx5_create_ttc_table(). Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table") Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com> --- drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c index e48afd620d7e..077fe908bf86 100644 --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c @@ -651,6 +651,7 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev, MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, inner_l4_type); break; default: + kvfree(ttc); return ERR_PTR(-EINVAL); } @@ -729,6 +730,7 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev, MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, outer_l4_type); break; default: + kvfree(ttc); return ERR_PTR(-EINVAL); } -- 2.34.1 ^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation 2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin @ 2025-04-15 13:46 ` Mark Bloch 2025-04-16 6:50 ` henry martin 0 siblings, 1 reply; 7+ messages in thread From: Mark Bloch @ 2025-04-15 13:46 UTC (permalink / raw) To: Henry Martin, saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba, pabeni Cc: netdev, linux-rdma, linux-kernel, amirtz, ayal On 15/04/2025 15:41, Henry Martin wrote: > Free ttc table memory when unsupported ttc_type is passed, to avoid > memory leak on the default error path in mlx5_create_inner_ttc_table() > and mlx5_create_ttc_table(). > > Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table") > Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com> > --- > drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c > index e48afd620d7e..077fe908bf86 100644 > --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c > +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c > @@ -651,6 +651,7 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev, > MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, inner_l4_type); > break; > default: > + kvfree(ttc); > return ERR_PTR(-EINVAL); > } > > @@ -729,6 +730,7 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev, > MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, outer_l4_type); > break; > default: > + kvfree(ttc); > return ERR_PTR(-EINVAL); > } > What about just moving the ttc allocation after the switch case? Mark ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation 2025-04-15 13:46 ` Mark Bloch @ 2025-04-16 6:50 ` henry martin 0 siblings, 0 replies; 7+ messages in thread From: henry martin @ 2025-04-16 6:50 UTC (permalink / raw) To: Mark Bloch Cc: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba, pabeni, netdev, linux-rdma, linux-kernel, amirtz, ayal > What about just moving the ttc allocation after the switch case? Thanks for the suggestion. Moving the allocation after the switch statement is indeed a cleaner approach. ^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2025-04-16 8:43 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-04-15 12:41 [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation Henry Martin
2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin
2025-04-15 13:45 ` Mark Bloch
2025-04-16 8:43 ` Tariq Toukan
2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin
2025-04-15 13:46 ` Mark Bloch
2025-04-16 6:50 ` henry martin
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox