Message ID | 20250526183607.66527-1-qasdev00@gmail.com |
---|---|
State | New |
Headers | show |
Series | net: ch9200: fix uninitialised access during mii_nway_restart | expand |
Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski <kuba@kernel.org>: On Mon, 26 May 2025 19:36:07 +0100 you wrote: > In mii_nway_restart() the code attempts to call > mii->mdio_read which is ch9200_mdio_read(). ch9200_mdio_read() > utilises a local buffer called "buff", which is initialised > with control_read(). However "buff" is conditionally > initialised inside control_read(): > > if (err == size) { > memcpy(data, buf, size); > } > > [...] Here is the summary with links: - net: ch9200: fix uninitialised access during mii_nway_restart https://git.kernel.org/netdev/net/c/9ad0452c0277 You are awesome, thank you!
diff --git a/drivers/net/usb/ch9200.c b/drivers/net/usb/ch9200.c index f69d9b902da0..a206ffa76f1b 100644 --- a/drivers/net/usb/ch9200.c +++ b/drivers/net/usb/ch9200.c @@ -178,6 +178,7 @@ static int ch9200_mdio_read(struct net_device *netdev, int phy_id, int loc) { struct usbnet *dev = netdev_priv(netdev); unsigned char buff[2]; + int ret; netdev_dbg(netdev, "%s phy_id:%02x loc:%02x\n", __func__, phy_id, loc); @@ -185,8 +186,10 @@ static int ch9200_mdio_read(struct net_device *netdev, int phy_id, int loc) if (phy_id != 0) return -ENODEV; - control_read(dev, REQUEST_READ, 0, loc * 2, buff, 0x02, - CONTROL_TIMEOUT_MS); + ret = control_read(dev, REQUEST_READ, 0, loc * 2, buff, 0x02, + CONTROL_TIMEOUT_MS); + if (ret < 0) + return ret; return (buff[0] | buff[1] << 8); }