Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1163842AbdDXAlC (ORCPT ); Sun, 23 Apr 2017 20:41:02 -0400 Received: from m12-11.163.com ([220.181.12.11]:60973 "EHLO m12-11.163.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1163769AbdDXAko (ORCPT ); Sun, 23 Apr 2017 20:40:44 -0400 From: Pan Bian To: Jussi Kivilinna , Kalle Valo , linux-wireless@vger.kernel.org, netdev@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Pan Bian Subject: [PATCH 1/1] rndis_wlan: add return value validation Date: Mon, 24 Apr 2017 08:40:28 +0800 Message-Id: <1492994428-16090-1-git-send-email-bianpan201603@163.com> X-Mailer: git-send-email 1.9.1 X-CM-TRANSID: C8CowAAnzip+Sf1Y2GwLAg--.46983S3 X-Coremail-Antispam: 1Uf129KBjvdXoW7Jw1UKw1kKw1DJF1xuF45Wrg_yoWkKFX_WF WxXFn7WrWrGw1jgw40kr43ZryFkry5XFn5Za1jqrWYqr17AFWIqrs5ZF98XrsrW342qryx WFnFvF17A392qjkaLaAFLSUrUUUUUb8apTn2vfkv8UJUUUU8Yxn0WfASr-VFAUDa7-sFnT 9fnUUvcSsGvfC2KfnxnUUI43ZEXa7IU5Bv35UUUUU== X-Originating-IP: [106.120.213.67] X-CM-SenderInfo: held01tdqsiiqwqtqiywtou0bp/xtbBXhfC91aDqPgCGAACsh Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1133 Lines: 31 From: Pan Bian Function create_singlethread_workqueue() will return a NULL pointer if there is no enough memory, and its return value should be validated before using. However, in function rndis_wlan_bind(), its return value is not checked. This may cause NULL dereference bugs. This patch fixes it. Signed-off-by: Pan Bian --- drivers/net/wireless/rndis_wlan.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/net/wireless/rndis_wlan.c b/drivers/net/wireless/rndis_wlan.c index 785334f..92a1bde 100644 --- a/drivers/net/wireless/rndis_wlan.c +++ b/drivers/net/wireless/rndis_wlan.c @@ -3427,6 +3427,10 @@ static int rndis_wlan_bind(struct usbnet *usbdev, struct usb_interface *intf) /* because rndis_command() sleeps we need to use workqueue */ priv->workqueue = create_singlethread_workqueue("rndis_wlan"); + if (!priv->workqueue) { + wiphy_free(wiphy); + return -ENOMEM; + } INIT_WORK(&priv->work, rndis_wlan_worker); INIT_DELAYED_WORK(&priv->dev_poller_work, rndis_device_poller); INIT_DELAYED_WORK(&priv->scan_work, rndis_get_scan_results); -- 1.9.1