From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9359E37DE97 for ; Fri, 7 Aug 2026 05:26:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786080368; cv=none; b=VluiCcbHvtrjpVSyyyZ6KqxLEJbQIAaUomvzskh8Pa+kLe1wNsF71SI/xiI7gfTaIgHcZDq7GsIlda2Lirb9kQAYw2g/r2wVgd7DjHjdNTGQ+WPe7OCYK+xAsLn8vG+4B2wLO7iU0uUsAomnRpeRHg5ZLaiZ3nIBbKJtzzbnkZQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786080368; c=relaxed/simple; bh=N9kYy5vVqmVHT5b2YlTC0fstsAGvx9Fj6BH6uRPvp2A=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=trkRo1ewZcsfseLuyXB/sDdC7Zf46Lmr+BPT7x5UTgT0WTxoz5HmQzlWA/BD/xHNwjK0KpeoPkeb4x1oK/NSw8xDMsWIdLXkSX8y46JUXqjFwrHG327ZKATwgzhWB1LciMuj8RvQFyRp9f27Sdytpq3nRHmJh2SxSHdXwJDgS5c= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Yte0/rWh; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Yte0/rWh" Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-38dc4553f62so3242506a91.0 for ; Thu, 06 Aug 2026 22:26:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786080364; x=1786685164; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Zpg2YgaZDfS9JXkJtXX3JMZ6Ihbw7Qug6CaZTA6PXXY=; b=Yte0/rWh4T5YvmomozsByw+mN/+UJphrAMs8zaKl494nX0pOK7muWJ7jhXs5Z+LfVE 7u9li4LRA6nFsngoyHmXhJ6G57ChEQHObiZ3lqtLFUwQMBB2X92OzkbxsMiCAwXNQJcj 5RWvxY5/TJAdkeAB2mBxf4wfwhUKiMTuFxV1qFPs5bW0kydvGE11+sgFVDvwlVbw5zei SYKlS5tFKlCi0zGHjoFwbzl2K/KT0gVOu+TXKE75gIhcWP7EBHleZVRz8MhLGUIiBpMb DZqLko6NHj+xb8DURKnm5L4FlpOwjxEhrnmE5lxpl+GGxgS/F7AtK/MIH01mocU0VUJP hyhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786080364; x=1786685164; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Zpg2YgaZDfS9JXkJtXX3JMZ6Ihbw7Qug6CaZTA6PXXY=; b=sKWlK6T3cgTdyP41nH1jhBnuduAep3IOnUPfLC80+POjNRUYVFvPm9HtHwuVRirf2Y QLCgDtwSW2jx7N6l1pYmIQllY+JDafhXJ611f5aN9O8mNJBzLHABvosNDed+iyOx9SCS SACQqVksd2AP33O2+zViXUqgYv5Kb9f6e6uFIp4nbpA4+uzhLxAUQdVLKQ8ucGr7oYbn NqbSecMURf0CJaFGWK8HCuqFQuN8q6JU/nJC8HqMaIJ4tMl/kZktkBDZYZd2dqaJFiJx 4nS9tj+l3E9XbNJ4JApySlVMdAyc+qoa2Xsvx7rcrVwhzFaV173GAGr4jaLbwQh0NCE+ xwZA== X-Forwarded-Encrypted: i=1; AHgh+RpOqVTu1pHP1/kdrrT4BQBVGsjW+INj3BaOtlVdbbd0NbArp+7YnjrcweR7pCFJT6Queb8Yg2lnje4DaY8=@vger.kernel.org X-Gm-Message-State: AOJu0YzPe2g7Ob2QBxPivaDSRx28KiNY9e+UL9zCC5wKC0qlkqGgJ/n0 6OnLIx+pgKjpaGsB81GSr2hSTolxEIRxhzTeHQyxTWsuyoI+ro8+PH7krzbtWIXdwO0= X-Gm-Gg: AR+sD130F9+lDq2DgYq0e8tu51whzt+CuhoLGvrhAVvktT1/hEWWUb4qlfx5NUiqeTZ EjdzfIDU9HR2fO0XxPxgecY92A7+SkeQB4nToqXmiMaLkx4aiuJhj3ED6TtyDA7TMxW+vqghFXK FQ9Dcfr2umzurJ2ZrYq9Yg0zX7io55xri8EYdniA0OKfITQADzRmT7asHbIh6JmgmFq8enNHcWk zBk3jnmRUng64NjrcsPOoryvfYLmH5+vMSy4OUJHX8kkjHkF/uF6HZd9D0sODfspHYXa6UbYTgq Ls8jV293RXLGIM33VpS7caHwdXeOse7PioeaQFAKyEE41LxMBIK9cKZYL3g++qeDr3X4EvnZzHN fH3Fx+cHSFvIYQjumfouZ9j4Z+pawlSjswEJ6W2R7FDE4QOMQ+7/vsvVHzaUM3qViGBY2Tc8qwW j7e/cpLkzc8Ct2/ddCGsxrQD0G6GTIOZUJ/AGbgu89+IEGF0Pf8K7wEdl02qo/MtCsJ1Ya/P8uP OzUBQijid0KsKNjrQsgC4r76ASq5Y2BRNYWyVGNxkwLWYfhasDzA3SuYw1S X-Received: by 2002:a17:90b:540e:b0:38e:6a30:4bbc with SMTP id 98e67ed59e1d1-3903c681346mr23457760a91.21.1786080364185; Thu, 06 Aug 2026 22:26:04 -0700 (PDT) Received: from bloom.localdomain ([2604:3d09:178e:e100::6868]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39085f5e33fsm3186836a91.14.2026.08.06.22.26.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 06 Aug 2026 22:26:03 -0700 (PDT) From: Ivy Lopez To: James.Bottomley@HansenPartnership.com, martin.petersen@oracle.com Cc: viro@zeniv.linux.org.uk, axboe@kernel.dk, bvanassche@acm.org, ching2048@areca.com.tw, linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, Ivy Lopez Subject: [PATCH] scsi: arcmsr: fix NULL deref on dma_alloc_coherent() failure in arcmsr_alloc_xor_buffer() Date: Thu, 6 Aug 2026 23:25:43 -0600 Message-ID: <20260807052543.62545-1-skunkolee@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit arcmsr_alloc_xor_buffer() does not check the return value of the initial dma_alloc_coherent() call before using it. If the allocation fails, the code performs pointer arithmetic on the NULL base (computing pXorPhys and pXorVirt) and later unconditionally dereferences it through pRamBuf to write hrbSignature and other fields, causing a NULL pointer dereference. Additionally, acb->xor_mega is set unconditionally before the allocation attempt, based only on firmware status bits. If the allocation fails, acb->xor_mega remains nonzero, so the later cleanup path in arcmsr_free_ccb_pool() and the message-config code in arcmsr_iop_confirm() will still enter their "if (acb->xor_mega)" branches and dereference the never-set acb->xorVirt/acb->xorPhys, a second NULL pointer dereference on the allocation failure path. Fix this by checking the initial dma_alloc_coherent() result and, on failure, resetting acb->xor_mega to 0 before returning -ENOMEM, so that no code path treats the XOR buffer as present when it was never allocated. Found by static analysis; no hardware reproducer. Signed-off-by: Ivy Lopez Cc: ching Huang --- drivers/scsi/arcmsr/arcmsr_hba.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/scsi/arcmsr/arcmsr_hba.c b/drivers/scsi/arcmsr/arcmsr_hba.c index 8aa948f06cac..40407b281839 100644 --- a/drivers/scsi/arcmsr/arcmsr_hba.c +++ b/drivers/scsi/arcmsr/arcmsr_hba.c @@ -771,6 +771,12 @@ static int arcmsr_alloc_xor_buffer(struct AdapterControlBlock *acb) (sizeof(struct XorHandle) * acb->xor_mega); dma_coherent = dma_alloc_coherent(&pdev->dev, acb->init2cfg_size, &dma_coherent_handle, GFP_KERNEL); + if (!dma_coherent) { + pr_info("arcmsr%d: alloc init2cfg buffer failed\n", + acb->host->host_no); + acb->xor_mega = 0; + return -ENOMEM; + } acb->xorVirt = dma_coherent; acb->xorPhys = dma_coherent_handle; pXorPhys = (struct Xor_sg *)((unsigned long)dma_coherent + -- 2.55.0