android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Hans de Goede 184f608a68 net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer
[ Upstream commit b6f56a44e4c1014b08859dcf04ed246500e310e5 ]

Since commit 7d5e9737ef ("net: rfkill: gpio: get the name and type from
device property") rfkill_find_type() gets called with the possibly
uninitialized "const char *type_name;" local variable.

On x86 systems when rfkill-gpio binds to a "BCM4752" or "LNV4752"
acpi_device, the rfkill->type is set based on the ACPI acpi_device_id:

        rfkill->type = (unsigned)id->driver_data;

and there is no "type" property so device_property_read_string() will fail
and leave type_name uninitialized, leading to a potential crash.

rfkill_find_type() does accept a NULL pointer, fix the potential crash
by initializing type_name to NULL.

Note likely sofar this has not been caught because:

1. Not many x86 machines actually have a "BCM4752"/"LNV4752" acpi_device
2. The stack happened to contain NULL where type_name is stored

Fixes: 7d5e9737ef ("net: rfkill: gpio: get the name and type from device property")
Cc: stable@vger.kernel.org
Cc: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Signed-off-by: Hans de Goede <hansg@kernel.org>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20250913113515.21698-1-hansg@kernel.org
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-02 13:34:32 +02:00
..
6lowpan
9p
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime 2025-08-28 16:21:16 +02:00
appletalk net: appletalk: Fix use-after-free in AARP proxy probe 2025-08-28 16:21:17 +02:00
atm net: atm: fix memory leak in atm_register_sysfs when device_register fail 2025-09-09 18:43:58 +02:00
ax25 ax25: properly unshare skbs in ax25_kiss_rcv() 2025-09-09 18:43:58 +02:00
batman-adv batman-adv: fix OOB read/write in network-coding decode 2025-09-09 18:43:59 +02:00
bluetooth Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() 2025-09-09 18:43:57 +02:00
bpf
bpfilter bpfilter: match bit size of bpfilter_umh to that of the kernel 2025-07-17 18:24:51 +02:00
bridge netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it 2025-06-27 11:02:46 +01:00
caif caif: reduce stack size, again 2025-08-28 16:21:19 +02:00
can can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails 2025-10-02 13:34:29 +02:00
ceph
core net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. 2025-10-02 13:34:27 +02:00
dcb
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa net: dsa: microchip: linearize skb for tail-tagging switches 2025-09-09 18:44:00 +02:00
ethernet
hsr
ieee802154
ife
ipv4 tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). 2025-10-02 13:34:30 +02:00
ipv6 icmp: fix icmp_ndo_send address translation for reply direction 2025-09-09 18:43:57 +02:00
iucv
kcm
key
l2tp
l3mdev
lapb
llc llc: fix data loss when reading from a socket in llc_ui_recvmsg() 2025-06-04 14:32:35 +02:00
mac80211 wifi: mac80211: fix incorrect type for ret 2025-10-02 13:34:30 +02:00
mac802154 mac802154: check local interfaces before deleting sdata list 2025-02-01 18:18:50 +01:00
mpls mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). 2025-06-27 11:02:57 +01:00
ncsi net: ncsi: Fix buffer overflow in fetching version id 2025-08-28 16:21:27 +02:00
netfilter netfilter: conntrack: helper: Replace -EEXIST by -EBUSY 2025-09-09 18:43:57 +02:00
netlabel calipso: unlock rcu before returning -EAFNOSUPPORT 2025-06-27 11:02:50 +01:00
netlink netlink: avoid infinite retry looping in netlink_unicast() 2025-08-28 16:21:23 +02:00
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
nfc NFC: nci: uart: Set tty->disc_data only in success path 2025-06-27 11:02:51 +01:00
nsh
openvswitch openvswitch: Fix unsafe attribute parsing in output_userspace() 2025-06-04 14:32:29 +02:00
packet net/packet: fix a race in packet_set_ring() and packet_notifier() 2025-08-28 16:21:23 +02:00
phonet phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() 2025-08-28 16:21:14 +02:00
psample
qrtr
rds rds: ib: Increment i_fastreg_wrs before bailing out 2025-10-02 13:34:31 +02:00
rfkill net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer 2025-10-02 13:34:32 +02:00
rose rose: fix dangling neighbour pointers in rose_rt_device_down() 2025-07-17 18:25:00 +02:00
rxrpc rxrpc: Fix oops due to non-existence of prealloc backlog struct 2025-07-17 18:25:02 +02:00
sched net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate 2025-08-28 16:21:37 +02:00
sctp sctp: initialize more fields in sctp_v6_from_sk() 2025-09-04 14:05:55 +02:00
smc
strparser
sunrpc xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create 2025-06-27 11:02:58 +01:00
switchdev
tipc tipc: Fix use-after-free in tipc_conn_close(). 2025-07-17 18:25:01 +02:00
tls bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls 2025-08-28 16:21:19 +02:00
unix
vmw_vsock vsock: Do not allow binding to VMADDR_PORT_ANY 2025-08-28 16:21:23 +02:00
wimax
wireless wifi: cfg80211: fix use-after-free in cmp_bss() 2025-09-09 18:43:56 +02:00
x25
xdp
xfrm xfrm: Sanitize marks before insert 2025-06-04 14:32:35 +02:00
compat.c
Kconfig
Makefile
socket.c
sysctl_net.c