* [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation
@ 2025-04-15 12:41 Henry Martin
2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin
2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin
0 siblings, 2 replies; 7+ messages in thread
From: Henry Martin @ 2025-04-15 12:41 UTC (permalink / raw)
To: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba,
pabeni
Cc: netdev, linux-rdma, linux-kernel, bsdhenrymartin, amirtz, ayal
This patch series addresses two issues in the
mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() functions:
1. A potential NULL pointer dereference if mlx5_get_flow_namespace()
returns NULL.
2. A memory leak in the error path when ttc_type is invalid (default:
switch case).
Henry Martin (2):
net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
net/mlx5: Fix memory leak in error path of ttc creation
drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
--
2.34.1
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
2025-04-15 12:41 [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation Henry Martin
@ 2025-04-15 12:41 ` Henry Martin
2025-04-15 13:45 ` Mark Bloch
2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin
1 sibling, 1 reply; 7+ messages in thread
From: Henry Martin @ 2025-04-15 12:41 UTC (permalink / raw)
To: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba,
pabeni
Cc: netdev, linux-rdma, linux-kernel, bsdhenrymartin, amirtz, ayal
Add NULL check for mlx5_get_flow_namespace() returns in
mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() to prevent
NULL pointer dereference.
Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
---
drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
index eb3bd9c7f66e..e48afd620d7e 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
@@ -655,6 +655,11 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
}
ns = mlx5_get_flow_namespace(dev, params->ns_type);
+ if (!ns) {
+ kvfree(ttc);
+ return ERR_PTR(-EOPNOTSUPP);
+ }
+
groups = use_l4_type ? &inner_ttc_groups[TTC_GROUPS_USE_L4_TYPE] :
&inner_ttc_groups[TTC_GROUPS_DEFAULT];
@@ -728,6 +733,11 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev,
}
ns = mlx5_get_flow_namespace(dev, params->ns_type);
+ if (!ns) {
+ kvfree(ttc);
+ return ERR_PTR(-EOPNOTSUPP);
+ }
+
groups = use_l4_type ? &ttc_groups[TTC_GROUPS_USE_L4_TYPE] :
&ttc_groups[TTC_GROUPS_DEFAULT];
--
2.34.1
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation
2025-04-15 12:41 [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation Henry Martin
2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin
@ 2025-04-15 12:41 ` Henry Martin
2025-04-15 13:46 ` Mark Bloch
1 sibling, 1 reply; 7+ messages in thread
From: Henry Martin @ 2025-04-15 12:41 UTC (permalink / raw)
To: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba,
pabeni
Cc: netdev, linux-rdma, linux-kernel, bsdhenrymartin, amirtz, ayal
Free ttc table memory when unsupported ttc_type is passed, to avoid
memory leak on the default error path in mlx5_create_inner_ttc_table()
and mlx5_create_ttc_table().
Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
---
drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
index e48afd620d7e..077fe908bf86 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
@@ -651,6 +651,7 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, inner_l4_type);
break;
default:
+ kvfree(ttc);
return ERR_PTR(-EINVAL);
}
@@ -729,6 +730,7 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev,
MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, outer_l4_type);
break;
default:
+ kvfree(ttc);
return ERR_PTR(-EINVAL);
}
--
2.34.1
^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin
@ 2025-04-15 13:45 ` Mark Bloch
2025-04-16 8:43 ` Tariq Toukan
0 siblings, 1 reply; 7+ messages in thread
From: Mark Bloch @ 2025-04-15 13:45 UTC (permalink / raw)
To: Henry Martin, saeedm, leon, tariqt, andrew+netdev, davem,
edumazet, kuba, pabeni
Cc: netdev, linux-rdma, linux-kernel, amirtz, ayal
On 15/04/2025 15:41, Henry Martin wrote:
> Add NULL check for mlx5_get_flow_namespace() returns in
> mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() to prevent
> NULL pointer dereference.
>
> Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table")
> Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
> ---
> drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 10 ++++++++++
> 1 file changed, 10 insertions(+)
>
> diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> index eb3bd9c7f66e..e48afd620d7e 100644
> --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> @@ -655,6 +655,11 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
> }
>
> ns = mlx5_get_flow_namespace(dev, params->ns_type);
> + if (!ns) {
> + kvfree(ttc);
> + return ERR_PTR(-EOPNOTSUPP);
> + }
> +
> groups = use_l4_type ? &inner_ttc_groups[TTC_GROUPS_USE_L4_TYPE] :
> &inner_ttc_groups[TTC_GROUPS_DEFAULT];
>
> @@ -728,6 +733,11 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev,
> }
>
> ns = mlx5_get_flow_namespace(dev, params->ns_type);
> + if (!ns) {
> + kvfree(ttc);
> + return ERR_PTR(-EOPNOTSUPP);
> + }
> +
> groups = use_l4_type ? &ttc_groups[TTC_GROUPS_USE_L4_TYPE] :
> &ttc_groups[TTC_GROUPS_DEFAULT];
>
Reviewed-by: Mark Bloch <mbloch@nvidia.com>
Mark
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation
2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin
@ 2025-04-15 13:46 ` Mark Bloch
2025-04-16 6:50 ` henry martin
0 siblings, 1 reply; 7+ messages in thread
From: Mark Bloch @ 2025-04-15 13:46 UTC (permalink / raw)
To: Henry Martin, saeedm, leon, tariqt, andrew+netdev, davem,
edumazet, kuba, pabeni
Cc: netdev, linux-rdma, linux-kernel, amirtz, ayal
On 15/04/2025 15:41, Henry Martin wrote:
> Free ttc table memory when unsupported ttc_type is passed, to avoid
> memory leak on the default error path in mlx5_create_inner_ttc_table()
> and mlx5_create_ttc_table().
>
> Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table")
> Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
> ---
> drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> index e48afd620d7e..077fe908bf86 100644
> --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> @@ -651,6 +651,7 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
> MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, inner_l4_type);
> break;
> default:
> + kvfree(ttc);
> return ERR_PTR(-EINVAL);
> }
>
> @@ -729,6 +730,7 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev,
> MLX5_CAP_NIC_RX_FT_FIELD_SUPPORT_2(dev, outer_l4_type);
> break;
> default:
> + kvfree(ttc);
> return ERR_PTR(-EINVAL);
> }
>
What about just moving the ttc allocation after the switch case?
Mark
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation
2025-04-15 13:46 ` Mark Bloch
@ 2025-04-16 6:50 ` henry martin
0 siblings, 0 replies; 7+ messages in thread
From: henry martin @ 2025-04-16 6:50 UTC (permalink / raw)
To: Mark Bloch
Cc: saeedm, leon, tariqt, andrew+netdev, davem, edumazet, kuba,
pabeni, netdev, linux-rdma, linux-kernel, amirtz, ayal
> What about just moving the ttc allocation after the switch case?
Thanks for the suggestion. Moving the allocation after the switch statement is
indeed a cleaner approach.
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
2025-04-15 13:45 ` Mark Bloch
@ 2025-04-16 8:43 ` Tariq Toukan
0 siblings, 0 replies; 7+ messages in thread
From: Tariq Toukan @ 2025-04-16 8:43 UTC (permalink / raw)
To: andrew+netdev, davem, edumazet, kuba, pabeni
Cc: netdev, linux-rdma, linux-kernel, amirtz, ayal, Gal Pressman,
Tariq Toukan, Leon Romanovsky, Saeed Mahameed, Henry Martin,
Mark Bloch
On 15/04/2025 16:45, Mark Bloch wrote:
>
>
> On 15/04/2025 15:41, Henry Martin wrote:
>> Add NULL check for mlx5_get_flow_namespace() returns in
>> mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() to prevent
>> NULL pointer dereference.
>>
>> Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table")
>> Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
>> ---
>> drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 10 ++++++++++
>> 1 file changed, 10 insertions(+)
>>
>> diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
>> index eb3bd9c7f66e..e48afd620d7e 100644
>> --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
>> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
>> @@ -655,6 +655,11 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
>> }
>>
>> ns = mlx5_get_flow_namespace(dev, params->ns_type);
>> + if (!ns) {
>> + kvfree(ttc);
>> + return ERR_PTR(-EOPNOTSUPP);
>> + }
>> +
>> groups = use_l4_type ? &inner_ttc_groups[TTC_GROUPS_USE_L4_TYPE] :
>> &inner_ttc_groups[TTC_GROUPS_DEFAULT];
>>
>> @@ -728,6 +733,11 @@ struct mlx5_ttc_table *mlx5_create_ttc_table(struct mlx5_core_dev *dev,
>> }
>>
>> ns = mlx5_get_flow_namespace(dev, params->ns_type);
>> + if (!ns) {
>> + kvfree(ttc);
>> + return ERR_PTR(-EOPNOTSUPP);
>> + }
>> +
>> groups = use_l4_type ? &ttc_groups[TTC_GROUPS_USE_L4_TYPE] :
>> &ttc_groups[TTC_GROUPS_DEFAULT];
>>
>
> Reviewed-by: Mark Bloch <mbloch@nvidia.com>
>
> Mark
>
netdev maintainers,
Note that Mark is covering me while I'm on vacation (for the coming ~10
days). Please accordingly honor his submissions and replies for mlx5
content.
In case this mail notification is not sufficient, please let us know
what extra action is required.
Happy Holidays,
Tariq
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2025-04-16 8:43 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-04-15 12:41 [PATCH v5 0/2] net/mlx5: Fix NULL dereference and memory leak in ttc_table creation Henry Martin
2025-04-15 12:41 ` [PATCH v5 1/2] net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Henry Martin
2025-04-15 13:45 ` Mark Bloch
2025-04-16 8:43 ` Tariq Toukan
2025-04-15 12:41 ` [PATCH v5 2/2] net/mlx5: Fix memory leak in error path of ttc creation Henry Martin
2025-04-15 13:46 ` Mark Bloch
2025-04-16 6:50 ` henry martin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox