From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2A321427D35; Sat, 28 Feb 2026 17:46:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772300789; cv=none; b=V9AIdXQDGlJGKCm5KPx3zVv/zd2u3+dP6vCccTazJnxbLZmkUikJlEr3pHszlbAwAfYt+pTIJh2PKnbri09PWxqcTz46d8FFAuoPR4ta0d52luDFsls/4gzYq4+13SHuH96MLYsnRbw1Tx50MlLTCHYe3mCNoNtuJIPzQBP6sB0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772300789; c=relaxed/simple; bh=Ez11OVOkHbz5VC+1582CGU9v60g9JtJcp2H6KwN942A=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=U58nPzS+8lIz72tOd/tDAZZGxk5VuOnVMfAamYEw0YEw9nhF2WeFkFqDRBkyTlgtEFfkW73Tz/zE6GKTivbYNLdvXS2k6P3aquLCEIYlNebHv35OJQJw3tgP9eLhWYBCSbh7YL82hqdH5DxEwouSJbzGaOqtjXXezs+ZR5NUqBI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Z77yvwg3; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Z77yvwg3" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 63960C19423; Sat, 28 Feb 2026 17:46:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1772300789; bh=Ez11OVOkHbz5VC+1582CGU9v60g9JtJcp2H6KwN942A=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=Z77yvwg3CfoMgYPZv4gvilwH/lnbIq5sCWnGdg8MGJPOT91fCjuD+1zdn4hT7Womj Oxt1X5R/Fu7nOPXVksdP12mZkXMf57ptGDYPNNDO3qLGhmx5xDnPO8wKZFarKDaRDq jESwMcFYiE9hmVefUfiN3DC4uMWs1KLXbLKTxkQ5hA56f0LalremZLgd91a6GHUWWX 93dv1MRO3JlDjobImCMK5qyM1+VrCvFXHthyuhPP4nalL+m4Y2tzD6CxhpS1tI+iwQ gV1zQXFjQvYmKN8SIAXuHYgNYs0BaolSH63NZtuBxAWeneQQDB9H9ZkzKe//+qBi8w nZ01vnKrc/1Vw== From: Sasha Levin To: linux-kernel@vger.kernel.org, stable@vger.kernel.org Cc: Ethan Nelson-Moore , Simon Horman , Paolo Abeni , Sasha Levin Subject: [PATCH 6.19 821/844] net: arcnet: com20020-pci: fix support for 2.5Mbit cards Date: Sat, 28 Feb 2026 12:32:14 -0500 Message-ID: <20260228173244.1509663-822-sashal@kernel.org> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260228173244.1509663-1-sashal@kernel.org> References: <20260228173244.1509663-1-sashal@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-stable: review X-Patchwork-Hint: Ignore Content-Transfer-Encoding: 8bit From: Ethan Nelson-Moore [ Upstream commit c7d9be66b71af490446127c6ffcb66d6bb71b8b9 ] Commit 8c14f9c70327 ("ARCNET: add com20020 PCI IDs with metadata") converted the com20020-pci driver to use a card info structure instead of a single flag mask in driver_data. However, it failed to take into account that in the original code, driver_data of 0 indicates a card with no special flags, not a card that should not have any card info structure. This introduced a null pointer dereference when cards with no flags were probed. Commit bd6f1fd5d33d ("net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()") then papered over this issue by rejecting cards with no driver_data instead of resolving the problem at its source. Fix the original issue by introducing a new card info structure for 2.5Mbit cards that does not set any flags and using it if no driver_data is present. Fixes: 8c14f9c70327 ("ARCNET: add com20020 PCI IDs with metadata") Fixes: bd6f1fd5d33d ("net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()") Cc: stable@vger.kernel.org Reviewed-by: Simon Horman Signed-off-by: Ethan Nelson-Moore Link: https://patch.msgid.link/20260213045510.32368-1-enelsonmoore@gmail.com Signed-off-by: Paolo Abeni Signed-off-by: Sasha Levin --- drivers/net/arcnet/com20020-pci.c | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/drivers/net/arcnet/com20020-pci.c b/drivers/net/arcnet/com20020-pci.c index 0472bcdff1307..b5729d6c0b47c 100644 --- a/drivers/net/arcnet/com20020-pci.c +++ b/drivers/net/arcnet/com20020-pci.c @@ -115,6 +115,8 @@ static const struct attribute_group com20020_state_group = { .attrs = com20020_state_attrs, }; +static struct com20020_pci_card_info card_info_2p5mbit; + static void com20020pci_remove(struct pci_dev *pdev); static int com20020pci_probe(struct pci_dev *pdev, @@ -140,7 +142,7 @@ static int com20020pci_probe(struct pci_dev *pdev, ci = (struct com20020_pci_card_info *)id->driver_data; if (!ci) - return -EINVAL; + ci = &card_info_2p5mbit; priv->ci = ci; mm = &ci->misc_map; @@ -347,6 +349,18 @@ static struct com20020_pci_card_info card_info_5mbit = { .flags = ARC_IS_5MBIT, }; +static struct com20020_pci_card_info card_info_2p5mbit = { + .name = "ARC-PCI", + .devcount = 1, + .chan_map_tbl = { + { + .bar = 2, + .offset = 0x00, + .size = 0x08, + }, + }, +}; + static struct com20020_pci_card_info card_info_sohard = { .name = "SOHARD SH ARC-PCI", .devcount = 1, -- 2.51.0