| From 963e2ecd362725ae09b7c85cd372151f927b67b9 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 4 Aug 2023 10:25:25 +0800 |
| Subject: IB/uverbs: Fix an potential error pointer dereference |
| |
| From: Xiang Yang <xiangyang3@huawei.com> |
| |
| [ Upstream commit 26b7d1a27167e7adf75b150755e05d2bc123ce55 ] |
| |
| smatch reports the warning below: |
| drivers/infiniband/core/uverbs_std_types_counters.c:110 |
| ib_uverbs_handler_UVERBS_METHOD_COUNTERS_READ() error: 'uattr' |
| dereferencing possible ERR_PTR() |
| |
| The return value of uattr maybe ERR_PTR(-ENOENT), fix this by checking |
| the value of uattr before using it. |
| |
| Fixes: ebb6796bd397 ("IB/uverbs: Add read counters support") |
| Signed-off-by: Xiang Yang <xiangyang3@huawei.com> |
| Link: https://lore.kernel.org/r/20230804022525.1916766-1-xiangyang3@huawei.com |
| Signed-off-by: Leon Romanovsky <leon@kernel.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/infiniband/core/uverbs_std_types_counters.c | 2 ++ |
| 1 file changed, 2 insertions(+) |
| |
| diff --git a/drivers/infiniband/core/uverbs_std_types_counters.c b/drivers/infiniband/core/uverbs_std_types_counters.c |
| index 999da9c798668..381aa57976417 100644 |
| --- a/drivers/infiniband/core/uverbs_std_types_counters.c |
| +++ b/drivers/infiniband/core/uverbs_std_types_counters.c |
| @@ -107,6 +107,8 @@ static int UVERBS_HANDLER(UVERBS_METHOD_COUNTERS_READ)( |
| return ret; |
| |
| uattr = uverbs_attr_get(attrs, UVERBS_ATTR_READ_COUNTERS_BUFF); |
| + if (IS_ERR(uattr)) |
| + return PTR_ERR(uattr); |
| read_attr.ncounters = uattr->ptr_attr.len / sizeof(u64); |
| read_attr.counters_buff = uverbs_zalloc( |
| attrs, array_size(read_attr.ncounters, sizeof(u64))); |
| -- |
| 2.40.1 |
| |