From c93446712acecb316468662801999a04950fbf36 Mon Sep 17 00:00:00 2001 From: Pratham Pratap Date: Tue, 7 Sep 2021 15:38:16 +0530 Subject: [PATCH] usb: xhci: Avoid NULL pointer access of sec event ring Consider a case where DUT is in a low memory condition and it is switching between host and none frequently. This can lead the driver to fail the allocation of primary event ring and go into error path where it will try to cleanup the event ring. Since secondary event ring was not even initialized, while fetching the entries to cleanup, it will lead to NULL pointer dereference. Avoid this by adding a NULL check for secondary event ring before fetching the entries and bailing out early from cleanup function. Change-Id: I21488d0e0a02347a392d890918c5c874b704795f Signed-off-by: Pratham Pratap --- drivers/usb/host/xhci-mem.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/usb/host/xhci-mem.c b/drivers/usb/host/xhci-mem.c index 4c99acc672ff..3c103ef030bb 100644 --- a/drivers/usb/host/xhci-mem.c +++ b/drivers/usb/host/xhci-mem.c @@ -1923,6 +1923,11 @@ static int sec_event_ring_cleanup(struct xhci_hcd *xhci, unsigned int intr_num) return -EINVAL; } + if (!xhci->sec_erst) { + xhci_err(xhci, "secondary ring is NULL or not initialized\n"); + return -EINVAL; + } + size = sizeof(struct xhci_erst_entry)*(xhci->sec_erst[intr_num].num_entries); if (xhci->sec_erst[intr_num].entries) {