| From 1b032c515526f284ab249a3876f37015650a52e9 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Wed, 28 Sep 2022 13:25:05 +0300 |
| Subject: crypto: nitrox - avoid double free on error path in |
| nitrox_sriov_init() |
| |
| From: Natalia Petrova <n.petrova@fintech.ru> |
| |
| [ Upstream commit 094528b6a5a755b1195a01e10b13597d67d1a0e6 ] |
| |
| If alloc_workqueue() fails in nitrox_mbox_init() it deallocates |
| ndev->iov.vfdev and returns error code, but then nitrox_sriov_init() |
| calls nitrox_sriov_cleanup() where ndev->iov.vfdev is deallocated |
| again. |
| |
| Fix this by nulling ndev->iov.vfdev after the first deallocation. |
| |
| Found by Linux Verification Center (linuxtesting.org) with SVACE. |
| |
| Fixes: 9e5de3e06e54 ("crypto: cavium/nitrox - Add mailbox...") |
| Signed-off-by: Natalia Petrova <n.petrova@fintech.ru> |
| Signed-off-by: Alexey Khoroshilov <khoroshilov@ispras.ru> |
| Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/crypto/cavium/nitrox/nitrox_mbx.c | 1 + |
| 1 file changed, 1 insertion(+) |
| |
| diff --git a/drivers/crypto/cavium/nitrox/nitrox_mbx.c b/drivers/crypto/cavium/nitrox/nitrox_mbx.c |
| index 2e9c0d214363..199fcec9b8d0 100644 |
| --- a/drivers/crypto/cavium/nitrox/nitrox_mbx.c |
| +++ b/drivers/crypto/cavium/nitrox/nitrox_mbx.c |
| @@ -191,6 +191,7 @@ int nitrox_mbox_init(struct nitrox_device *ndev) |
| ndev->iov.pf2vf_wq = alloc_workqueue("nitrox_pf2vf", 0, 0); |
| if (!ndev->iov.pf2vf_wq) { |
| kfree(ndev->iov.vfdev); |
| + ndev->iov.vfdev = NULL; |
| return -ENOMEM; |
| } |
| /* enable pf2vf mailbox interrupts */ |
| -- |
| 2.35.1 |
| |