fb_deferred_io_init() allocates deferred I/O state, populating
info->fbdefio_state, or leaving it NULL if an error occurs.

Currently xenfb_probe() ignores its return value.

Therefore if an error arises in fb_deferred_io_init() (for instance, due
to an allocation failure) info->fbdefio_state is left NULL.

When the file is subsequently opened, fb_open() will dereference a NULL
pointer (calling fb_deferred_io_open()).

Fix this by checking for the error.

Fixes: 56c134f7f1b5 ("fbdev: Track deferred-I/O pages in pageref struct")
Cc: <[email protected]>
Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
---
 drivers/video/fbdev/xen-fbfront.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/video/fbdev/xen-fbfront.c 
b/drivers/video/fbdev/xen-fbfront.c
index 4385976277ac..7ef909d4242d 100644
--- a/drivers/video/fbdev/xen-fbfront.c
+++ b/drivers/video/fbdev/xen-fbfront.c
@@ -443,7 +443,11 @@ static int xenfb_probe(struct xenbus_device *dev,
        }
 
        fb_info->fbdefio = &xenfb_defio;
-       fb_deferred_io_init(fb_info);
+       ret = fb_deferred_io_init(fb_info);
+       if (ret < 0) {
+               xenbus_dev_fatal(dev, ret, "fb_deferred_io_init");
+               goto error_cmap;
+       }
 
        xenfb_init_shared_page(info, fb_info);
 
@@ -465,6 +469,7 @@ static int xenfb_probe(struct xenbus_device *dev,
 
 error_fb:
        fb_deferred_io_cleanup(fb_info);
+error_cmap:
        fb_dealloc_cmap(&fb_info->cmap);
        framebuffer_release(fb_info);
 error_nomem:

-- 
2.55.0

Reply via email to