summaryrefslogtreecommitdiff
path: root/include
diff options
context:
space:
mode:
authorAnthony Krowiak <akrowiak@linux.ibm.com>2026-08-12 16:02:39 -0400
committerChristian Borntraeger <borntraeger@linux.ibm.com>2026-08-13 16:04:33 +0200
commitdd6f4ef6f8a37412909ad787c837332fb070159c (patch)
tree7ce142759f82e28dc1c74b45601b88098d32f29c /include
parent917f509bfb88048094dbb85c4e9dbc4d6fe4a886 (diff)
s390/vfio-ap: Fix NULL deref in status_show() during queue probe
When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference. Fix this by acquiring the update locks before calling sysfs_create_group(). The status_show() function acquires guests_lock before reading the driver data, so any concurrent read will block until after dev_set_drvdata() has been called and the update locks are released. As a bonus, the APQN no longer needs to be read from the queue struct after allocation — it can be read directly from apdev before allocation and stored in a local variable, which is then assigned to q->apqn once the allocation succeeds. Fixes: 260f3ea141382 ("s390/vfio-ap: move probe and remove callbacks to vfio_ap_ops.c") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com> Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com> Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Diffstat (limited to 'include')
0 files changed, 0 insertions, 0 deletions