Hans de Goede
184f608a68
net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer
...
[ Upstream commit b6f56a44e4c1014b08859dcf04ed246500e310e5 ]
Since commit 7d5e9737ef ("net: rfkill: gpio: get the name and type from
device property") rfkill_find_type() gets called with the possibly
uninitialized "const char *type_name;" local variable.
On x86 systems when rfkill-gpio binds to a "BCM4752" or "LNV4752"
acpi_device, the rfkill->type is set based on the ACPI acpi_device_id:
rfkill->type = (unsigned)id->driver_data;
and there is no "type" property so device_property_read_string() will fail
and leave type_name uninitialized, leading to a potential crash.
rfkill_find_type() does accept a NULL pointer, fix the potential crash
by initializing type_name to NULL.
Note likely sofar this has not been caught because:
1. Not many x86 machines actually have a "BCM4752"/"LNV4752" acpi_device
2. The stack happened to contain NULL where type_name is stored
Fixes: 7d5e9737ef ("net: rfkill: gpio: get the name and type from device property")
Cc: stable@vger.kernel.org
Cc: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Signed-off-by: Hans de Goede <hansg@kernel.org>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20250913113515.21698-1-hansg@kernel.org
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-02 13:34:32 +02:00
..
6lowpan
9p
802
net: 802: LLC+SNAP OID:PID lookup on start of skb data
2025-02-01 18:18:45 +01:00
8021q
net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime
2025-08-28 16:21:16 +02:00
appletalk
net: appletalk: Fix use-after-free in AARP proxy probe
2025-08-28 16:21:17 +02:00
atm
net: atm: fix memory leak in atm_register_sysfs when device_register fail
2025-09-09 18:43:58 +02:00
ax25
ax25: properly unshare skbs in ax25_kiss_rcv()
2025-09-09 18:43:58 +02:00
batman-adv
batman-adv: fix OOB read/write in network-coding decode
2025-09-09 18:43:59 +02:00
bluetooth
Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
2025-09-09 18:43:57 +02:00
bpf
bpfilter
bpfilter: match bit size of bpfilter_umh to that of the kernel
2025-07-17 18:24:51 +02:00
bridge
netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
2025-06-27 11:02:46 +01:00
caif
caif: reduce stack size, again
2025-08-28 16:21:19 +02:00
can
can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails
2025-10-02 13:34:29 +02:00
ceph
core
net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod.
2025-10-02 13:34:27 +02:00
dcb
dccp
net: fix data-races around sk->sk_forward_alloc
2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa
net: dsa: microchip: linearize skb for tail-tagging switches
2025-09-09 18:44:00 +02:00
ethernet
hsr
ieee802154
ife
ipv4
tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().
2025-10-02 13:34:30 +02:00
ipv6
icmp: fix icmp_ndo_send address translation for reply direction
2025-09-09 18:43:57 +02:00
iucv
kcm
key
l2tp
l3mdev
lapb
llc
llc: fix data loss when reading from a socket in llc_ui_recvmsg()
2025-06-04 14:32:35 +02:00
mac80211
wifi: mac80211: fix incorrect type for ret
2025-10-02 13:34:30 +02:00
mac802154
mac802154: check local interfaces before deleting sdata list
2025-02-01 18:18:50 +01:00
mpls
mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
2025-06-27 11:02:57 +01:00
ncsi
net: ncsi: Fix buffer overflow in fetching version id
2025-08-28 16:21:27 +02:00
netfilter
netfilter: conntrack: helper: Replace -EEXIST by -EBUSY
2025-09-09 18:43:57 +02:00
netlabel
calipso: unlock rcu before returning -EAFNOSUPPORT
2025-06-27 11:02:50 +01:00
netlink
netlink: avoid infinite retry looping in netlink_unicast()
2025-08-28 16:21:23 +02:00
netrom
netrom: check buffer length before accessing it
2025-01-09 13:23:35 +01:00
nfc
NFC: nci: uart: Set tty->disc_data only in success path
2025-06-27 11:02:51 +01:00
nsh
openvswitch
openvswitch: Fix unsafe attribute parsing in output_userspace()
2025-06-04 14:32:29 +02:00
packet
net/packet: fix a race in packet_set_ring() and packet_notifier()
2025-08-28 16:21:23 +02:00
phonet
phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept()
2025-08-28 16:21:14 +02:00
psample
qrtr
rds
rds: ib: Increment i_fastreg_wrs before bailing out
2025-10-02 13:34:31 +02:00
rfkill
net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer
2025-10-02 13:34:32 +02:00
rose
rose: fix dangling neighbour pointers in rose_rt_device_down()
2025-07-17 18:25:00 +02:00
rxrpc
rxrpc: Fix oops due to non-existence of prealloc backlog struct
2025-07-17 18:25:02 +02:00
sched
net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate
2025-08-28 16:21:37 +02:00
sctp
sctp: initialize more fields in sctp_v6_from_sk()
2025-09-04 14:05:55 +02:00
smc
strparser
sunrpc
xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
2025-06-27 11:02:58 +01:00
switchdev
tipc
tipc: Fix use-after-free in tipc_conn_close().
2025-07-17 18:25:01 +02:00
tls
bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
2025-08-28 16:21:19 +02:00
unix
vmw_vsock
vsock: Do not allow binding to VMADDR_PORT_ANY
2025-08-28 16:21:23 +02:00
wimax
wireless
wifi: cfg80211: fix use-after-free in cmp_bss()
2025-09-09 18:43:56 +02:00
x25
xdp
xfrm
xfrm: Sanitize marks before insert
2025-06-04 14:32:35 +02:00
compat.c
Kconfig
Makefile
socket.c
sysctl_net.c