4.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Gustavo A. R. Silva" <garsi...@embeddedor.com>


[ Upstream commit dd92d5ea20ef8a42be7aeda08c669c586c730451 ]

Check return values from call to devm_kzalloc() and devm_kmemup()
in order to prevent a NULL pointer dereference.

This issue was detected using Coccinelle and the following semantic patch:

@@
expression x;
identifier fld;
@@

* x = devm_kzalloc(...);
   ... when != x == NULL
   x->fld

Fixes: 7ba9df54b091 ("iio: multiplexer: new iio category and iio-mux driver")
Signed-off-by: Gustavo A. R. Silva <garsi...@embeddedor.com>
Acked-by: Peter Rosin <p...@axentia.se>
Signed-off-by: Jonathan Cameron <jonathan.came...@huawei.com>
Signed-off-by: Sasha Levin <alexander.le...@verizon.com>
Signed-off-by: Greg Kroah-Hartman <gre...@linuxfoundation.org>
---
 drivers/iio/multiplexer/iio-mux.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/iio/multiplexer/iio-mux.c
+++ b/drivers/iio/multiplexer/iio-mux.c
@@ -285,6 +285,9 @@ static int mux_configure_channel(struct
        child->ext_info_cache = devm_kzalloc(dev,
                                             sizeof(*child->ext_info_cache) *
                                             num_ext_info, GFP_KERNEL);
+       if (!child->ext_info_cache)
+               return -ENOMEM;
+
        for (i = 0; i < num_ext_info; ++i) {
                child->ext_info_cache[i].size = -1;
 
@@ -309,6 +312,9 @@ static int mux_configure_channel(struct
 
                child->ext_info_cache[i].data = devm_kmemdup(dev, page, ret + 1,
                                                             GFP_KERNEL);
+               if (!child->ext_info_cache[i].data)
+                       return -ENOMEM;
+
                child->ext_info_cache[i].data[ret] = 0;
                child->ext_info_cache[i].size = ret;
        }


Reply via email to