Commit 888d8903 authored by Aaron Ma's avatar Aaron Ma Committed by Felix Fietkau

wifi: mt76: mt7921: fix error code of return in mt7921_acpi_read

Kernel NULL pointer dereference when ACPI SAR table isn't implemented well.
Fix the error code of return to mark the ACPI SAR table as invalid.

[    5.077128] mt7921e 0000:06:00.0: sar cnt = 0
[    5.077381] BUG: kernel NULL pointer dereference, address:
0000000000000004
[    5.077630] #PF: supervisor read access in kernel mode
[    5.077883] #PF: error_code(0x0000) - not-present page
[    5.078138] PGD 0 P4D 0
[    5.078398] Oops: 0000 [#1] PREEMPT SMP NOPTI
[    5.079202] RIP: 0010:mt7921_init_acpi_sar+0x106/0x220
[mt7921_common]
...
[    5.080786] Call Trace:
[    5.080786]  <TASK>
[    5.080786]  mt7921_register_device+0x37d/0x490 [mt7921_common]
[    5.080786]  mt7921_pci_probe.part.0+0x2ee/0x310 [mt7921e]
[    5.080786]  mt7921_pci_probe+0x52/0x70 [mt7921e]
[    5.080786]  local_pci_probe+0x47/0x90
[    5.080786]  pci_call_probe+0x55/0x190
[    5.080786]  pci_device_probe+0x84/0x120

Fixes: f965333e ("mt76: mt7921: introduce ACPI SAR support")
Signed-off-by: default avatarAaron Ma <aaron.ma@canonical.com>
Signed-off-by: default avatarFelix Fietkau <nbd@nbd.name>
parent a97a467a
...@@ -33,14 +33,17 @@ mt7921_acpi_read(struct mt7921_dev *dev, u8 *method, u8 **tbl, u32 *len) ...@@ -33,14 +33,17 @@ mt7921_acpi_read(struct mt7921_dev *dev, u8 *method, u8 **tbl, u32 *len)
sar_root->package.elements[0].type != ACPI_TYPE_INTEGER) { sar_root->package.elements[0].type != ACPI_TYPE_INTEGER) {
dev_err(mdev->dev, "sar cnt = %d\n", dev_err(mdev->dev, "sar cnt = %d\n",
sar_root->package.count); sar_root->package.count);
ret = -EINVAL;
goto free; goto free;
} }
if (!*tbl) { if (!*tbl) {
*tbl = devm_kzalloc(mdev->dev, sar_root->package.count, *tbl = devm_kzalloc(mdev->dev, sar_root->package.count,
GFP_KERNEL); GFP_KERNEL);
if (!*tbl) if (!*tbl) {
ret = -ENOMEM;
goto free; goto free;
}
} }
if (len) if (len)
*len = sar_root->package.count; *len = sar_root->package.count;
...@@ -52,9 +55,9 @@ mt7921_acpi_read(struct mt7921_dev *dev, u8 *method, u8 **tbl, u32 *len) ...@@ -52,9 +55,9 @@ mt7921_acpi_read(struct mt7921_dev *dev, u8 *method, u8 **tbl, u32 *len)
break; break;
*(*tbl + i) = (u8)sar_unit->integer.value; *(*tbl + i) = (u8)sar_unit->integer.value;
} }
free:
ret = (i == sar_root->package.count) ? 0 : -EINVAL; ret = (i == sar_root->package.count) ? 0 : -EINVAL;
free:
kfree(sar_root); kfree(sar_root);
return ret; return ret;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment