diff mbox series

scsi: qla2xxx: Fix possible null-pointer dereferences in qla2x00_alloc_fcport()

Message ID 20190729084451.29290-1-baijiaju1990@gmail.com (mailing list archive)
State Mainlined
Commit e82f04ec6ba91065fd33a6201ffd7cab840e1475
Headers show
Series scsi: qla2xxx: Fix possible null-pointer dereferences in qla2x00_alloc_fcport() | expand

Commit Message

Jia-Ju Bai July 29, 2019, 8:44 a.m. UTC
In qla2x00_alloc_fcport(), fcport is assigned to NULL in the error
handling code on line 4880:
    fcport = NULL;

Then fcport is used on lines 4883-4886:
    INIT_WORK(&fcport->del_work, qla24xx_delete_sess_fn);
	INIT_WORK(&fcport->reg_work, qla_register_fcport_fn);
	INIT_LIST_HEAD(&fcport->gnl_entry);
	INIT_LIST_HEAD(&fcport->list);

Thus, possible null-pointer dereferences may occur.

To fix these bugs, qla2x00_alloc_fcport() directly returns NULL 
in the error handling code.

These bugs are found by a static analysis tool STCheck written by us.

Signed-off-by: Jia-Ju Bai <baijiaju1990@gmail.com>
---
 drivers/scsi/qla2xxx/qla_init.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Martin K. Petersen July 30, 2019, 4:50 p.m. UTC | #1
Jia-Ju,

> In qla2x00_alloc_fcport(), fcport is assigned to NULL in the error
> handling code on line 4880:
>     fcport = NULL;

Applied to 5.3/scsi-fixes. Thanks!
diff mbox series

Patch

diff --git a/drivers/scsi/qla2xxx/qla_init.c b/drivers/scsi/qla2xxx/qla_init.c
index 4059655639d9..da83034d4759 100644
--- a/drivers/scsi/qla2xxx/qla_init.c
+++ b/drivers/scsi/qla2xxx/qla_init.c
@@ -4877,7 +4877,7 @@  qla2x00_alloc_fcport(scsi_qla_host_t *vha, gfp_t flags)
 		ql_log(ql_log_warn, vha, 0xd049,
 		    "Failed to allocate ct_sns request.\n");
 		kfree(fcport);
-		fcport = NULL;
+		return NULL;
 	}
 
 	INIT_WORK(&fcport->del_work, qla24xx_delete_sess_fn);