Guard the memset() in ibmvfc_deregister_channel() behind a check of
scrq->msgs.handle to prevent a NULL dereference when the function is
called on a queue that was never allocated, such as async_sub_crq when
multi-queue is disabled or initialization failed before
ibmvfc_alloc_queue() was reached.

Signed-off-by: Dave Marquardt <[email protected]>
Signed-off-by: Tyrel Datwyler <[email protected]>
---
 drivers/scsi/ibmvscsi/ibmvfc-core.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/scsi/ibmvscsi/ibmvfc-core.c 
b/drivers/scsi/ibmvscsi/ibmvfc-core.c
index 17c49a0ed4f4..ef76f8c194eb 100644
--- a/drivers/scsi/ibmvscsi/ibmvfc-core.c
+++ b/drivers/scsi/ibmvscsi/ibmvfc-core.c
@@ -6481,8 +6481,10 @@ static void ibmvfc_deregister_channel(struct ibmvfc_host 
*vhost,
                dev_err(dev, "Failed to free sub-crq[%d]: rc=%ld\n", index, rc);
 
        /* Clean out the queue */
-       memset(scrq->msgs.crq, 0, PAGE_SIZE);
-       scrq->cur = 0;
+       if (scrq->msgs.handle) {
+               memset(scrq->msgs.crq, 0, PAGE_SIZE);
+               scrq->cur = 0;
+       }
 
        LEAVE;
 }
-- 
2.55.0


Reply via email to