mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jacob Keller <jacob.e.keller@intel.com>
To: Thomas Fourier <fourier.thomas@gmail.com>
Cc: <stable@vger.kernel.org>, Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@kernel.org>,
	"Jakub Kicinski" <kuba@kernel.org>,
	Paolo Abeni <pabeni@redhat.com>, Jeff Garzik <jeff@garzik.org>,
	Thomas Bogendoerfer <tsbogend@alpha.franken.de>,
	"open list:NETWORKING DRIVERS" <netdev@vger.kernel.org>,
	open list <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH net] net: ethernet: i825xx: Fix dma_alloc_coherent() size
Date: Tue, 6 Oct 2026 14:44:55 -0700	[thread overview]
Message-ID: <818a214a-b4bc-4e85-b4c0-2270c736d03b@intel.com> (raw)
In-Reply-To: <20261006143247.54724-2-fourier.thomas@gmail.com>

On 10/6/2026 7:32 AM, Thomas Fourier wrote:
> In sni_82596_probe(), the lp->dma buffer is allocated with
> dma_alloc_coherent() and with size sizeof(struct i596_dma), and possibly
> freed in the error path with the same size. However, in
> sni_82596_driver_remove(), the same buffer is freed but with size
> sizeof(struct i596_private). This error may leave the freed buffers
> mapped, leaking a resource and allowing the device to access freed
> memory.
> 
> Change the length in sni_82596_driver_remove() to
> sizeof(struct i596_dma).
> 
> This patch was compile tested only, and found by hand.
> 
> Fixes: f2ec8030085a ("Ethernet driver for EISA only SNI RM200/RM400 machines")

Hmm. At first this didn't seem like the right fixes tag. The offending
code was changed multiple times before being caught.

> Cc: <stable@vger.kernel.org>
> Signed-off-by: Thomas Fourier <fourier.thomas@gmail.com>
> ---
>  drivers/net/ethernet/i825xx/sni_82596.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/ethernet/i825xx/sni_82596.c b/drivers/net/ethernet/i825xx/sni_82596.c
> index baa598988f47..73e1e153cb78 100644
> --- a/drivers/net/ethernet/i825xx/sni_82596.c
> +++ b/drivers/net/ethernet/i825xx/sni_82596.c
> @@ -159,7 +159,7 @@ static void sni_82596_driver_remove(struct platform_device *pdev)
>  	struct i596_private *lp = netdev_priv(dev);
>  
>  	unregister_netdev(dev);
> -	dma_free_coherent(&pdev->dev, sizeof(struct i596_private), lp->dma,
> +	dma_free_coherent(&pdev->dev, sizeof(struct i596_dma), lp->dma,
>  			  lp->dma_addr);

This dma_free_coherent call was added by commit 48d15814dd0f ("lib82596:
move DMA allocation into the callers of i82596_probe").

But I guess previous to this it was using dma_free_attrs inside of the
probe function and that also appears to have also mistakenly used a
different size.

Digging deeper, this was changed to dma_free_attrs as part of commit
7f683b920479 ("i825xx: switch to switch to dma_alloc_attrs"), previously
using DMA_FREE. But even prior to this it still had the incorrect size.

Strictly, a backport to that old version would have merge conflicts due
to the changes, but it is accurate that the bug exists all the way back
to 2.6.23... Hopefully no one is going to bother trying though and every
currently supported stable release has the current code and should apply
clean.

Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>

>  	iounmap(lp->ca);
>  	iounmap(lp->mpu_port);


      reply	other threads:[~2026-10-06 21:45 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 14:32 Thomas Fourier
2026-10-06 21:44 ` Jacob Keller [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=818a214a-b4bc-4e85-b4c0-2270c736d03b@intel.com \
    --to=jacob.e.keller@intel.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@kernel.org \
    --cc=fourier.thomas@gmail.com \
    --cc=jeff@garzik.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=stable@vger.kernel.org \
    --cc=tsbogend@alpha.franken.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®