[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20141126.151732.832218547273018783.davem@davemloft.net>
Date: Wed, 26 Nov 2014 15:17:32 -0500 (EST)
From: David Miller <davem@...emloft.net>
To: mlindner@...vell.com
Cc: netdev@...r.kernel.org
Subject: Re: [PATCH net-next] sky2: Fix crash inside sky2_rx_clean
From: Mirko Lindner <mlindner@...vell.com>
Date: Wed, 26 Nov 2014 15:13:38 +0100
> If sky2->tx_le = pci_alloc_consistent() or sky2->tx_ring = kcalloc() in
> sky2_alloc_buffers() fails, sky2->rx_ring = kcalloc() will never be called.
> In this error case handling, sky2_rx_clean() is called from within
> sky2_free_buffers().
>
> In sky2_rx_clean() we find the following:
>
> ...
> memset(sky2->rx_le, 0, RX_LE_BYTES);
> ...
>
> This results in a memset using a NULL pointer and will crash the system.
>
> Signed-off-by: Mirko Lindner <mlindner@...vell.com>
Applied, thanks.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists