kcalloc but does not check for failure. If the allocation fails, the pointer remains NULL but the function returns success. Subsequent code using this buffer will dereference a NULL pointer, causing a kernel oops. Add a check to return -ENOMEM if the allocation fails.
Signed-off-by: Geoffrey McRae <[email protected]> Cc: Alex Deucher <[email protected]> Cc: Christian König <[email protected]> --- drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c index 6c0dde3786e3..261ddc19c840 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c @@ -250,11 +250,16 @@ int amdgpu_mes_init(struct amdgpu_device *adev) goto error_doorbell; } } - } - adev->gfx.mec.mes_hung_db_array = - kcalloc(amdgpu_mes_get_hung_queue_db_array_size(adev), - sizeof(u32), GFP_KERNEL); + adev->gfx.mec.mes_hung_db_array = + kcalloc(amdgpu_mes_get_hung_queue_db_array_size(adev), + sizeof(u32), GFP_KERNEL); + + if (!adev->gfx.mec.mes_hung_db_array) { + r = -ENOMEM; + goto error_doorbell; + } + } return 0; -- 2.43.0
