]> git.hungrycats.org Git - linux/commitdiff
staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc
authorShyam Sunder Reddy Padira <shyamsunderreddypadira@gmail.com>
Tue, 14 Apr 2026 07:13:06 +0000 (12:43 +0530)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 14 Sep 2026 11:36:19 +0000 (13:36 +0200)
commit bc851db06045a40c18233dd76ef0562d7f8bb6db upstream.

The return value of kzalloc_flex() is used without
ensuring that the allocation succeeded, and the
pointer is dereferenced unconditionally.

Guard the access to the allocated structure to
avoid a potential NULL pointer dereference if the
allocation fails.

Fixes: 980cd426a257 ("staging: rtl8723bs: replace rtw_zmalloc() with kzalloc()")
Cc: stable <stable@kernel.org>
Signed-off-by: Shyam Sunder Reddy Padira <shyamsunderreddypadira@gmail.com>
Reviewed-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/20260414071308.4781-2-shyamsunderreddypadira@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/staging/rtl8723bs/os_dep/osdep_service.c

index 24467d353bafbc297b85b1b438ec0dbc30cc5efb..a9502ed7e000bcaa52915b87994e5b08f0d0f2f5 100644 (file)
@@ -224,7 +224,8 @@ struct rtw_cbuf *rtw_cbuf_alloc(u32 size)
        struct rtw_cbuf *cbuf;
 
        cbuf = kzalloc(struct_size(cbuf, bufs, size), GFP_KERNEL);
-       cbuf->size = size;
+       if (cbuf)
+               cbuf->size = size;
 
        return cbuf;
 }