Skip to content

Commit fa8fb60

Browse files
lynnjoergroedel
authored andcommitted
iommu/iova: Add NULL check in iova_magazine_free()
When iova_domain_init_rcaches() fails to allocate an iova_magazine during the initialization of per-cpu rcaches, it jumps to out_err and calls free_iova_rcaches() for cleanup. In free_iova_rcaches(), the code iterates through all possible CPUs to free both cpu_rcache->loaded and cpu_rcache->prev. However, if the original allocation failed mid-way through the CPU loop, the pointers for the remaining CPUs remain NULL. Since kmem_cache_free() does not explicitly handle NULL pointers like kfree() does, passing these NULL pointers leads to a kernel paging request fault. Add a NULL check in iova_magazine_free() to safely handle partially initialized rcaches in error paths. Signed-off-by: lynn <liulynn@google.com> Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
1 parent 199036a commit fa8fb60

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

drivers/iommu/iova.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -611,7 +611,8 @@ static struct iova_magazine *iova_magazine_alloc(gfp_t flags)
611611

612612
static void iova_magazine_free(struct iova_magazine *mag)
613613
{
614-
kmem_cache_free(iova_magazine_cache, mag);
614+
if (mag)
615+
kmem_cache_free(iova_magazine_cache, mag);
615616
}
616617

617618
static void

0 commit comments

Comments
 (0)