[PATCH wireless] wifi: mt76: fix NULL dereference reading napi_threaded in debugfs
Devin Wittmayer
lucid_duck at justthetip.ca
Sat Oct 10 10:19:47 PDT 2026
The napi_threaded debugfs file is created for every device, but only
devices that set up NAPI allocate the netdev behind it. SDIO devices
never do, and neither did USB devices before their receive path moved
to NAPI. Reading the file on one of them oopses:
BUG: kernel NULL pointer dereference, address: 0000000000000343
RIP: 0010:mt76_napi_threaded_get+0x10/0x30 [mt76]
Call Trace:
simple_attr_read
debugfs_attr_read
vfs_read
Refuse the read when there is no NAPI device, as the write side already
does for these devices.
Fixes: 08f116c9ea6d ("wifi: mt76: un-embedd netdev from mt76_dev")
Cc: stable at vger.kernel.org
Signed-off-by: Devin Wittmayer <lucid_duck at justthetip.ca>
---
I read the file as root after fresh boots. Patched builds used each
kernel's own source.
USB, 6.12 to 7.2, stock 13 kernels oops, 38 of 38 boots
USB, 6.12 to 7.2, patched 9 kernels refused, 270 of 270 reads
USB, 6.8, stock 1 kernel reads 0, 30 of 30
USB, 7.3-rc, stock+patched 1 kernel reads 1, 60 of 60
PCIe, stock+patched 2 machines reads 1, 93 of 93
distros Debian, Kali, Alpine, Ubuntu, Fedora, Arch, CachyOS,
Raspberry Pi OS
machines x86 and arm64, bare metal and VMs
adapters MT7921AU and MT7925U on USB, MT7922 and MT7927 on PCIe
compilers gcc and clang
drivers/net/wireless/mediatek/mt76/debugfs.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/debugfs.c b/drivers/net/wireless/mediatek/mt76/debugfs.c
index a5ac6ca86735..d04199b50a29 100644
--- a/drivers/net/wireless/mediatek/mt76/debugfs.c
+++ b/drivers/net/wireless/mediatek/mt76/debugfs.c
@@ -44,6 +44,9 @@ mt76_napi_threaded_get(void *data, u64 *val)
{
struct mt76_dev *dev = data;
+ if (!dev->napi_dev)
+ return -EOPNOTSUPP;
+
*val = dev->napi_dev->threaded;
return 0;
}
--
2.56.0
More information about the Linux-mediatek
mailing list