aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJesper Juhl <jj@chaosbits.net>2011-01-24 15:14:33 -0500
committerJesse Barnes <jbarnes@virtuousgeek.org>2011-02-08 16:08:05 -0500
commit7c867c8899e873652ef98a890d2e647c092bec25 (patch)
tree482e3c673dd58243be6ed73915fd0c92dc44ca9a
parentc13ff2ff3ad1479f222e18f9caba3db5af68d549 (diff)
PCI: Avoid potential NULL pointer dereference in pci_scan_bridge
pci_add_new_bus() calls pci_alloc_child_bus() which calls pci_alloc_bus() that allocates memory dynamically with kzalloc(). The return value of kzalloc() is the pointer that's eventually returned from pci_add_new_bus(), so since kzalloc() can fail and return NULL so can pci_add_new_bus(). Thus we may end up dereferencing a NULL pointer in drivers/pci/probe.c::pci_scan_bridge(). Seems to me we should test for this and bail out if it happens rather than crashing. Also removed some trailing whitespace that bugged me while looking at this. Signed-off-by: Jesper Juhl <jj@chaosbits.net> Signed-off-by: Jesse Barnes <jbarnes@virtuousgeek.org>
-rw-r--r--drivers/pci/probe.c4
1 files changed, 3 insertions, 1 deletions
diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c
index c84900da3c59..44cbbbaa499d 100644
--- a/drivers/pci/probe.c
+++ b/drivers/pci/probe.c
@@ -764,6 +764,8 @@ int __devinit pci_scan_bridge(struct pci_bus *bus, struct pci_dev *dev, int max,
764 if (pci_find_bus(pci_domain_nr(bus), max+1)) 764 if (pci_find_bus(pci_domain_nr(bus), max+1))
765 goto out; 765 goto out;
766 child = pci_add_new_bus(bus, dev, ++max); 766 child = pci_add_new_bus(bus, dev, ++max);
767 if (!child)
768 goto out;
767 buses = (buses & 0xff000000) 769 buses = (buses & 0xff000000)
768 | ((unsigned int)(child->primary) << 0) 770 | ((unsigned int)(child->primary) << 0)
769 | ((unsigned int)(child->secondary) << 8) 771 | ((unsigned int)(child->secondary) << 8)
@@ -777,7 +779,7 @@ int __devinit pci_scan_bridge(struct pci_bus *bus, struct pci_dev *dev, int max,
777 buses &= ~0xff000000; 779 buses &= ~0xff000000;
778 buses |= CARDBUS_LATENCY_TIMER << 24; 780 buses |= CARDBUS_LATENCY_TIMER << 24;
779 } 781 }
780 782
781 /* 783 /*
782 * We need to blast all three values with a single write. 784 * We need to blast all three values with a single write.
783 */ 785 */