• Bart Van Assche's avatar
    scsi: qla2xxx: Fix a NULL pointer dereference · d1436e45
    Bart Van Assche authored
    BUG: KASAN: null-ptr-deref in qla24xx_handle_plogi_done_event+0x134/0x9f0 [qla2xxx]
    Read of size 4 at addr 00000000000000a0 by task swapper/2/0
    
    CPU: 2 PID: 0 Comm: swapper/2 Not tainted 5.2.0-dbg+ #1
    Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
    Call Trace:
     <IRQ>
     dump_stack+0x8a/0xd6
     __kasan_report.cold+0x5/0x41
     kasan_report+0x16/0x20
     __asan_load4+0x7e/0x80
     qla24xx_handle_plogi_done_event+0x134/0x9f0 [qla2xxx]
     qla2x00_els_dcmd2_sp_done+0x15f/0x230 [qla2xxx]
     qla24xx_els_ct_entry+0x3b3/0x610 [qla2xxx]
     qla24xx_process_response_queue+0x514/0x10e0 [qla2xxx]
     qla24xx_msix_rsp_q+0x80/0x100 [qla2xxx]
     __handle_irq_event_percpu+0x72/0x450
     handle_irq_event_percpu+0x74/0xf0
     handle_irq_event+0x5e/0x8f
     handle_edge_irq+0x13a/0x320
     handle_irq+0x30/0x40
     do_IRQ+0x91/0x190
     common_interrupt+0xf/0xf
     </IRQ>
    RIP: 0010:default_idle+0x31/0x230
    
    Fixes: 8777e431 ("scsi: qla2xxx: Migrate NVME N2N handling into state machine") # v4.19.
    Cc: Himanshu Madhani <hmadhani@marvell.com>
    Signed-off-by: default avatarBart Van Assche <bvanassche@acm.org>
    Tested-by: default avatarHimanshu Madhani <hmadhani@marvell.com>
    Reviewed-by: default avatarHimanshu Madhani <hmadhani@marvell.com>
    Signed-off-by: default avatarMartin K. Petersen <martin.petersen@oracle.com>
    d1436e45
qla_iocb.c 99.5 KB