From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933042AbXHDSeM (ORCPT ); Sat, 4 Aug 2007 14:34:12 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1765527AbXHDSdG (ORCPT ); Sat, 4 Aug 2007 14:33:06 -0400 Received: from fk-out-0910.google.com ([209.85.128.187]:44971 "EHLO fk-out-0910.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1765643AbXHDSdB (ORCPT ); Sat, 4 Aug 2007 14:33:01 -0400 DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:from:to:subject:user-agent:cc:mime-version:content-disposition:date:content-type:content-transfer-encoding:message-id; b=MiPXOW/bfQ0qgnbQlsnHEoTgyPqa4ahPcjbvXNZrulICnUMjXCngBsyICiBxgA7BaFOpK0aTR52oQQ4p1bvt+aGX/DAhmeeuQajuZZ8klRjyr2f+cIiKx7OYCimAkf1f5b7ghJOeHaZ2Ax+lXKK6fhl9BvUNVFEE1ZSk19Rq8Z0= From: Jesper Juhl To: Andrew Morton Subject: [PATCH][RESEND] Avoid possible NULL pointer deref in 3c359 driver User-Agent: KMail/1.9.7 Cc: Linux Kernel Mailing List , Mike Phillips , netdev@vger.kernel.org, linux-tr@linuxtr.net, Jesper Juhl , davem@davemloft.net MIME-Version: 1.0 Content-Disposition: inline Date: Sat, 4 Aug 2007 20:31:05 +0200 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Message-Id: <200708042031.05784.jesper.juhl@gmail.com> Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org (Resending old patch originally submitted at 1/7-2007 02:19) In xl_freemem(), if dev_if is NULL, the line struct xl_private *xl_priv =(struct xl_private *)dev->priv; will cause a NULL pointer dereference. However, if we move that assignment below the 'if' statement that tests for a NULL 'dev', then that NULL deref can never happen. It never hurts to be safe :-) Signed-off-by: Jesper Juhl --- diff --git a/drivers/net/tokenring/3c359.c b/drivers/net/tokenring/3c359.c index e22a3f5..671f4da 100644 --- a/drivers/net/tokenring/3c359.c +++ b/drivers/net/tokenring/3c359.c @@ -1044,15 +1044,17 @@ static void xl_freemem(struct net_device *dev) static irqreturn_t xl_interrupt(int irq, void *dev_id) { struct net_device *dev = (struct net_device *)dev_id; - struct xl_private *xl_priv =(struct xl_private *)dev->priv; - u8 __iomem * xl_mmio = xl_priv->xl_mmio ; - u16 intstatus, macstatus ; + struct xl_private *xl_priv; + u8 __iomem * xl_mmio; + u16 intstatus, macstatus; if (!dev) { - printk(KERN_WARNING "Device structure dead, aaahhhh !\n") ; + printk(KERN_WARNING "3c359: Device structure dead, aaahhhh!\n"); return IRQ_NONE; } + xl_priv = (struct xl_private *)dev->priv; + xl_mmio = xl_priv->xl_mmio; intstatus = readw(xl_mmio + MMIO_INTSTATUS) ; if (!(intstatus & 1)) /* We didn't generate the interrupt */