[PATCH] net/iavf: check for NULL pointer before dereference
Loftus, Ciara
ciara.loftus at intel.com
Fri Jul 10 15:19:34 CEST 2026
> Subject: [PATCH] net/iavf: check for NULL pointer before dereference
check-git-log complains NULL --> null
>
> Static analysis with Coverity flags a possible NULL pointer dereference
> of "hdr1" when handling IPv4 or IPv6 fragements in
> iavf_fdir_parse_pattern. This is likely a false positive, since the
> flow pattern protocol sequences are checked before this function is
> called, so all paths leading to a hdr1 dereference start with an
> ethernet protocol, which sets hdr1 to a non-NULL value.
>
> However, this is a rather brittle situation, so to prevent any future
> issues if a new set of allowed protocols is added with IP but no
> Ethernet matching patterns, add explicit NULL checks for hdr1 before
> it's used each time.
>
> Coverity Id: 503768
"issue" instead of "id"
>
> Signed-off-by: Bruce Richardson <bruce.richardson at intel.com>
Acked-by: Ciara Loftus <ciara.loftus at intel.com>
> ---
> drivers/net/intel/iavf/iavf_fdir.c | 16 ++++++++++++++++
> 1 file changed, 16 insertions(+)
>
> diff --git a/drivers/net/intel/iavf/iavf_fdir.c b/drivers/net/intel/iavf/iavf_fdir.c
> index 8940132dff..ea620863ca 100644
> --- a/drivers/net/intel/iavf/iavf_fdir.c
> +++ b/drivers/net/intel/iavf/iavf_fdir.c
> @@ -806,6 +806,14 @@ iavf_fdir_parse_pattern(__rte_unused struct
> iavf_adapter *ad,
> * ethertype, if the spec and mask is valid,
> * set ethertype into input set.
> */
> + /* ETH should be present via pattern pre-
> validation. */
> + if (hdr1 == NULL) {
> + rte_flow_error_set(error, EINVAL,
> +
> RTE_FLOW_ERROR_TYPE_ITEM,
> + item,
> + "Missing ETH header before
> IPv4 fragment.");
> + return -rte_errno;
> + }
> input_set |= IAVF_INSET_ETHERTYPE;
>
> VIRTCHNL_ADD_PROTO_HDR_FIELD_BIT(hdr1, ETH,
> ETHERTYPE);
> @@ -911,6 +919,14 @@ iavf_fdir_parse_pattern(__rte_unused struct
> iavf_adapter *ad,
> * ethertype, if the spec and mask is valid,
> * set ethertype into input set.
> */
> + /* ETH should be present via pattern pre-
> validation. */
> + if (hdr1 == NULL) {
> + rte_flow_error_set(error, EINVAL,
> +
> RTE_FLOW_ERROR_TYPE_ITEM,
> + item,
> + "Missing ETH header before
> IPv6 fragment.");
> + return -rte_errno;
> + }
> input_set |= IAVF_INSET_ETHERTYPE;
>
> VIRTCHNL_ADD_PROTO_HDR_FIELD_BIT(hdr1, ETH,
> ETHERTYPE);
> --
> 2.53.0
More information about the dev
mailing list