net: wan: fix error return code of uhdlc_init()
[ Upstream commit 62765d3955
]
When priv->rx_skbuff or priv->tx_skbuff is NULL, no error return code of
uhdlc_init() is assigned.
To fix this bug, ret is assigned with -ENOMEM in these cases.
Reported-by: TOTE Robot <oslab@tsinghua.edu.cn>
Signed-off-by: Jia-Ju Bai <baijiaju1990@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
55ef4f2c5d
commit
ef822bd0d8
@ -169,13 +169,17 @@ static int uhdlc_init(struct ucc_hdlc_private *priv)
|
|||||||
|
|
||||||
priv->rx_skbuff = kzalloc(priv->rx_ring_size * sizeof(*priv->rx_skbuff),
|
priv->rx_skbuff = kzalloc(priv->rx_ring_size * sizeof(*priv->rx_skbuff),
|
||||||
GFP_KERNEL);
|
GFP_KERNEL);
|
||||||
if (!priv->rx_skbuff)
|
if (!priv->rx_skbuff) {
|
||||||
|
ret = -ENOMEM;
|
||||||
goto free_ucc_pram;
|
goto free_ucc_pram;
|
||||||
|
}
|
||||||
|
|
||||||
priv->tx_skbuff = kzalloc(priv->tx_ring_size * sizeof(*priv->tx_skbuff),
|
priv->tx_skbuff = kzalloc(priv->tx_ring_size * sizeof(*priv->tx_skbuff),
|
||||||
GFP_KERNEL);
|
GFP_KERNEL);
|
||||||
if (!priv->tx_skbuff)
|
if (!priv->tx_skbuff) {
|
||||||
|
ret = -ENOMEM;
|
||||||
goto free_rx_skbuff;
|
goto free_rx_skbuff;
|
||||||
|
}
|
||||||
|
|
||||||
priv->skb_curtx = 0;
|
priv->skb_curtx = 0;
|
||||||
priv->skb_dirtytx = 0;
|
priv->skb_dirtytx = 0;
|
||||||
|
Reference in New Issue
Block a user