| From e76d08db453bd75f5e42f43ba7eeb2ed00cbcee2 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Mon, 16 May 2022 17:22:41 +0800 |
| Subject: staging: rtl8712: fix uninit-value in r871xu_drv_init() |
| |
| From: Wang Cheng <wanngchenng@gmail.com> |
| |
| [ Upstream commit 0458e5428e5e959d201a40ffe71d762a79ecedc4 ] |
| |
| When 'tmpU1b' returns from r8712_read8(padapter, EE_9346CR) is 0, |
| 'mac[6]' will not be initialized. |
| |
| BUG: KMSAN: uninit-value in r871xu_drv_init+0x2d54/0x3070 drivers/staging/rtl8712/usb_intf.c:541 |
| r871xu_drv_init+0x2d54/0x3070 drivers/staging/rtl8712/usb_intf.c:541 |
| usb_probe_interface+0xf19/0x1600 drivers/usb/core/driver.c:396 |
| really_probe+0x653/0x14b0 drivers/base/dd.c:596 |
| __driver_probe_device+0x3e9/0x530 drivers/base/dd.c:752 |
| driver_probe_device drivers/base/dd.c:782 [inline] |
| __device_attach_driver+0x79f/0x1120 drivers/base/dd.c:899 |
| bus_for_each_drv+0x2d6/0x3f0 drivers/base/bus.c:427 |
| __device_attach+0x593/0x8e0 drivers/base/dd.c:970 |
| device_initial_probe+0x4a/0x60 drivers/base/dd.c:1017 |
| bus_probe_device+0x17b/0x3e0 drivers/base/bus.c:487 |
| device_add+0x1fff/0x26e0 drivers/base/core.c:3405 |
| usb_set_configuration+0x37e9/0x3ed0 drivers/usb/core/message.c:2170 |
| usb_generic_driver_probe+0x13c/0x300 drivers/usb/core/generic.c:238 |
| usb_probe_device+0x309/0x570 drivers/usb/core/driver.c:293 |
| really_probe+0x653/0x14b0 drivers/base/dd.c:596 |
| __driver_probe_device+0x3e9/0x530 drivers/base/dd.c:752 |
| driver_probe_device drivers/base/dd.c:782 [inline] |
| __device_attach_driver+0x79f/0x1120 drivers/base/dd.c:899 |
| bus_for_each_drv+0x2d6/0x3f0 drivers/base/bus.c:427 |
| __device_attach+0x593/0x8e0 drivers/base/dd.c:970 |
| device_initial_probe+0x4a/0x60 drivers/base/dd.c:1017 |
| bus_probe_device+0x17b/0x3e0 drivers/base/bus.c:487 |
| device_add+0x1fff/0x26e0 drivers/base/core.c:3405 |
| usb_new_device+0x1b8e/0x2950 drivers/usb/core/hub.c:2566 |
| hub_port_connect drivers/usb/core/hub.c:5358 [inline] |
| hub_port_connect_change drivers/usb/core/hub.c:5502 [inline] |
| port_event drivers/usb/core/hub.c:5660 [inline] |
| hub_event+0x58e3/0x89e0 drivers/usb/core/hub.c:5742 |
| process_one_work+0xdb6/0x1820 kernel/workqueue.c:2307 |
| worker_thread+0x10b3/0x21e0 kernel/workqueue.c:2454 |
| kthread+0x3c7/0x500 kernel/kthread.c:377 |
| ret_from_fork+0x1f/0x30 |
| |
| Local variable mac created at: |
| r871xu_drv_init+0x1771/0x3070 drivers/staging/rtl8712/usb_intf.c:394 |
| usb_probe_interface+0xf19/0x1600 drivers/usb/core/driver.c:396 |
| |
| KMSAN: uninit-value in r871xu_drv_init |
| https://syzkaller.appspot.com/bug?id=3cd92b1d85428b128503bfa7a250294c9ae00bd8 |
| |
| Reported-by: <syzbot+6f5ecd144854c0d8580b@syzkaller.appspotmail.com> |
| Tested-by: <syzbot+6f5ecd144854c0d8580b@syzkaller.appspotmail.com> |
| Reviewed-by: Dan Carpenter <dan.carpenter@oracle.com> |
| Signed-off-by: Wang Cheng <wanngchenng@gmail.com> |
| Link: https://lore.kernel.org/r/14c3886173dfa4597f0704547c414cfdbcd11d16.1652618244.git.wanngchenng@gmail.com |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/staging/rtl8712/usb_intf.c | 6 +++--- |
| 1 file changed, 3 insertions(+), 3 deletions(-) |
| |
| diff --git a/drivers/staging/rtl8712/usb_intf.c b/drivers/staging/rtl8712/usb_intf.c |
| index d0ba42dfafeb..7b7cb2a7db60 100644 |
| --- a/drivers/staging/rtl8712/usb_intf.c |
| +++ b/drivers/staging/rtl8712/usb_intf.c |
| @@ -569,13 +569,13 @@ static int r871xu_drv_init(struct usb_interface *pusb_intf, |
| } else { |
| AutoloadFail = false; |
| } |
| - if (((mac[0] == 0xff) && (mac[1] == 0xff) && |
| + if ((!AutoloadFail) || |
| + ((mac[0] == 0xff) && (mac[1] == 0xff) && |
| (mac[2] == 0xff) && (mac[3] == 0xff) && |
| (mac[4] == 0xff) && (mac[5] == 0xff)) || |
| ((mac[0] == 0x00) && (mac[1] == 0x00) && |
| (mac[2] == 0x00) && (mac[3] == 0x00) && |
| - (mac[4] == 0x00) && (mac[5] == 0x00)) || |
| - (!AutoloadFail)) { |
| + (mac[4] == 0x00) && (mac[5] == 0x00))) { |
| mac[0] = 0x00; |
| mac[1] = 0xe0; |
| mac[2] = 0x4c; |
| -- |
| 2.35.1 |
| |