Message ID | 20170921220158.19341-1-colin.king@canonical.com |
---|---|
State | Awaiting Upstream, archived |
Delegated to: | David Miller |
Headers | show |
Series | e1000: avoid null pointer dereference on invalid stat type | expand |
On Thu, Sep 21, 2017 at 11:01:58PM +0100, Colin King wrote: > @@ -1837,12 +1838,13 @@ static void e1000_get_ethtool_stats(struct net_device *netdev, > p = (char *)adapter + stat->stat_offset; > break; > default: > + p = NULL; > WARN_ONCE(1, "Invalid E1000 stat type: %u index %d\n", > stat->type, i); > break; > } > > - if (stat->sizeof_stat == sizeof(u64)) > + if (p && stat->sizeof_stat == sizeof(u64)) > data[i] = *(u64 *)p; > else > data[i] = *(u32 *)p; ^^^^^^^^ The else side will still crash. regards, dan carpenter
On 22/09/17 12:50, Dan Carpenter wrote: > On Thu, Sep 21, 2017 at 11:01:58PM +0100, Colin King wrote: >> @@ -1837,12 +1838,13 @@ static void e1000_get_ethtool_stats(struct net_device *netdev, >> p = (char *)adapter + stat->stat_offset; >> break; >> default: >> + p = NULL; >> WARN_ONCE(1, "Invalid E1000 stat type: %u index %d\n", >> stat->type, i); >> break; >> } >> >> - if (stat->sizeof_stat == sizeof(u64)) >> + if (p && stat->sizeof_stat == sizeof(u64)) >> data[i] = *(u64 *)p; >> else >> data[i] = *(u32 *)p; > ^^^^^^^^ > > The else side will still crash. > > regards, > dan carpenter > Thanks, stupid me. I'll fix that up.
diff --git a/drivers/net/ethernet/intel/e1000/e1000_ethtool.c b/drivers/net/ethernet/intel/e1000/e1000_ethtool.c index ec8aa4562cc9..2ef6f08b580b 100644 --- a/drivers/net/ethernet/intel/e1000/e1000_ethtool.c +++ b/drivers/net/ethernet/intel/e1000/e1000_ethtool.c @@ -1824,11 +1824,12 @@ static void e1000_get_ethtool_stats(struct net_device *netdev, { struct e1000_adapter *adapter = netdev_priv(netdev); int i; - char *p = NULL; const struct e1000_stats *stat = e1000_gstrings_stats; e1000_update_stats(adapter); for (i = 0; i < E1000_GLOBAL_STATS_LEN; i++) { + char *p; + switch (stat->type) { case NETDEV_STATS: p = (char *)netdev + stat->stat_offset; @@ -1837,12 +1838,13 @@ static void e1000_get_ethtool_stats(struct net_device *netdev, p = (char *)adapter + stat->stat_offset; break; default: + p = NULL; WARN_ONCE(1, "Invalid E1000 stat type: %u index %d\n", stat->type, i); break; } - if (stat->sizeof_stat == sizeof(u64)) + if (p && stat->sizeof_stat == sizeof(u64)) data[i] = *(u64 *)p; else data[i] = *(u32 *)p;