mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
wan: wanxl: Only reset hardware after BAR mapping
wanxl_pci_init_one() stores the freshly allocated card in driver data
before the PLX BAR is mapped. Several early probe failures then unwind
through wanxl_pci_remove_one(), including failure to allocate the coherent
status area or to restore the DMA mask.
wanxl_pci_remove_one() unconditionally calls wanxl_reset(), and
wanxl_reset() dereferences card->plx. On those early failures card->plx
is still NULL, so the error path can dereference a NULL MMIO pointer.
Only issue the hardware reset once the BAR mapping exists. The remaining
cleanup in wanxl_pci_remove_one() already checks whether later resources
were allocated.
This issue was found by a static analysis checker and confirmed by
manual source review.
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Link: https://patch.msgid.link/20260708143415.3169358-1-ruoyuw560@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
a61b4db34a
commit
91957b89da
|
|
@ -514,7 +514,8 @@ static void wanxl_pci_remove_one(struct pci_dev *pdev)
|
|||
if (card->irq)
|
||||
free_irq(card->irq, card);
|
||||
|
||||
wanxl_reset(card);
|
||||
if (card->plx)
|
||||
wanxl_reset(card);
|
||||
|
||||
for (i = 0; i < RX_QUEUE_LENGTH; i++)
|
||||
if (card->rx_skbs[i]) {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user