From: Jacob Keller <jacob.e.keller@intel.com>
To: Meghana Malladi <m-malladi@ti.com>, <dan.carpenter@linaro.org>,
<javier.carrasco.cruz@gmail.com>, <diogo.ivo@siemens.com>,
<horms@kernel.org>, <john.fastabend@gmail.com>, <hawk@kernel.org>,
<daniel@iogearbox.net>, <ast@kernel.org>,
<richardcochran@gmail.com>, <pabeni@redhat.com>,
<kuba@kernel.org>, <edumazet@google.com>, <davem@davemloft.net>,
<andrew+netdev@lunn.ch>
Cc: <bpf@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<netdev@vger.kernel.org>, <linux-arm-kernel@lists.infradead.org>,
<srk@ti.com>, Vignesh Raghavendra <vigneshr@ti.com>,
Roger Quadros <rogerq@kernel.org>, <danishanwar@ti.com>
Subject: Re: [PATCH net v4 2/3] net: ti: icssg-prueth: Fix possible NULL pointer dereference inside emac_xmit_xdp_frame()
Date: Tue, 15 Apr 2025 10:42:27 -0700 [thread overview]
Message-ID: <0cd1637c-91b7-4029-b3df-143b7c9e02ef@intel.com> (raw)
In-Reply-To: <20250415090543.717991-3-m-malladi@ti.com>
On 4/15/2025 2:05 AM, Meghana Malladi wrote:
> There is an error check inside emac_xmit_xdp_frame() function which
> is called when the driver wants to transmit XDP frame, to check if
> the allocated tx descriptor is NULL, if true to exit and return
> ICSSG_XDP_CONSUMED implying failure in transmission.
>
> In this case trying to free a descriptor which is NULL will result
> in kernel crash due to NULL pointer dereference. Fix this error handling
> and increase netdev tx_dropped stats in the caller of this function
> if the function returns ICSSG_XDP_CONSUMED.
>
> Fixes: 62aa3246f462 ("net: ti: icssg-prueth: Add XDP support")
> Reported-by: Dan Carpenter <dan.carpenter@linaro.org>
> Closes: https://lore.kernel.org/all/70d8dd76-0c76-42fc-8611-9884937c82f5@stanley.mountain/
> Signed-off-by: Meghana Malladi <m-malladi@ti.com>
> Reviewed-by: Simon Horman <horms@kernel.org>
> Reviewed-by: Roger Quadros <rogerq@kernel.org>
> ---
>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
> Changes from v3 (v4-v3):
> - Collected RB tag from Roger Quadros <rogerq@kernel.org>
>
> drivers/net/ethernet/ti/icssg/icssg_common.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/net/ethernet/ti/icssg/icssg_common.c b/drivers/net/ethernet/ti/icssg/icssg_common.c
> index ec643fb69d30..b4be76e13a2f 100644
> --- a/drivers/net/ethernet/ti/icssg/icssg_common.c
> +++ b/drivers/net/ethernet/ti/icssg/icssg_common.c
> @@ -583,7 +583,7 @@ u32 emac_xmit_xdp_frame(struct prueth_emac *emac,
> first_desc = k3_cppi_desc_pool_alloc(tx_chn->desc_pool);
> if (!first_desc) {
> netdev_dbg(ndev, "xdp tx: failed to allocate descriptor\n");
> - goto drop_free_descs; /* drop */
> + return ICSSG_XDP_CONSUMED; /* drop */
> }
>
> if (page) { /* already DMA mapped by page_pool */
> @@ -671,8 +671,10 @@ static u32 emac_run_xdp(struct prueth_emac *emac, struct xdp_buff *xdp,
>
> q_idx = smp_processor_id() % emac->tx_ch_num;
> result = emac_xmit_xdp_frame(emac, xdpf, page, q_idx);
> - if (result == ICSSG_XDP_CONSUMED)
> + if (result == ICSSG_XDP_CONSUMED) {
> + ndev->stats.tx_dropped++;
> goto drop;
> + }
>
> dev_sw_netstats_rx_add(ndev, xdpf->len);
> return result;
next prev parent reply other threads:[~2025-04-15 17:42 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-15 9:05 [PATCH net v4 0/3] Bug fixes from XDP and perout series Meghana Malladi
2025-04-15 9:05 ` [PATCH net v4 1/3] net: ti: icssg-prueth: Fix kernel warning while bringing down network interface Meghana Malladi
2025-04-15 17:41 ` Jacob Keller
2025-04-15 9:05 ` [PATCH net v4 2/3] net: ti: icssg-prueth: Fix possible NULL pointer dereference inside emac_xmit_xdp_frame() Meghana Malladi
2025-04-15 17:42 ` Jacob Keller [this message]
2025-04-15 9:05 ` [PATCH net v4 3/3] net: ti: icss-iep: Fix possible NULL pointer dereference for perout request Meghana Malladi
2025-04-15 17:45 ` Jacob Keller
2025-04-17 10:30 ` [PATCH net v4 0/3] Bug fixes from XDP and perout series patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0cd1637c-91b7-4029-b3df-143b7c9e02ef@intel.com \
--to=jacob.e.keller@intel.com \
--cc=andrew+netdev@lunn.ch \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=dan.carpenter@linaro.org \
--cc=daniel@iogearbox.net \
--cc=danishanwar@ti.com \
--cc=davem@davemloft.net \
--cc=diogo.ivo@siemens.com \
--cc=edumazet@google.com \
--cc=hawk@kernel.org \
--cc=horms@kernel.org \
--cc=javier.carrasco.cruz@gmail.com \
--cc=john.fastabend@gmail.com \
--cc=kuba@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=m-malladi@ti.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=richardcochran@gmail.com \
--cc=rogerq@kernel.org \
--cc=srk@ti.com \
--cc=vigneshr@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®