From: syzbot <syzbot+87bb32e345aa80c0554b@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Forwarded: [PATCH] PCI: Handle dev_set_name() failure in pci_setup_device()
Date: Sat, 25 Jul 2026 03:06:50 -0700 [thread overview]
Message-ID: <6a648aba.073198cf.94f0f.0013.GAE@google.com> (raw)
In-Reply-To: <697018fc.050a0220.706b.0003.GAE@google.com>
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: [PATCH] PCI: Handle dev_set_name() failure in pci_setup_device()
Author: rihyeon8648@gmail.com
#syz test
pci_setup_device() calls dev_set_name() but ignores its return value.
dev_set_name() allocates the name with kvasprintf() and can fail, leaving
dev->kobj.name NULL.
Enumeration then continues with an unnamed device. device_add() rejects
it with -EINVAL because dev_name() returns NULL and pci_bus_type has no
->dev_name callback, but pci_device_add() only WARNs about that failure:
pci (null): [8086:2934] type 00 class 0x0c0300 conventional PCI endpoint
pci (null): BAR 4 [io 0xc0e0-0xc0ff]
------------[ cut here ]------------
ret < 0
WARNING: drivers/pci/probe.c:2768 at pci_device_add+0x133b/0x1810
Call Trace:
pci_scan_single_device+0x1d0/0x240
pci_scan_slot+0x1c9/0x7c0
pci_scan_child_bus_extend+0x6b/0x7b0
pci_rescan_bus+0x18/0x40
rescan_store+0xfb/0x130
The device was already put on bus->devices before device_add() ran and is
not removed from it, so pci_bus_add_devices() later in the same
pci_rescan_bus() call picks it up and hands it to __device_attach(), which
dereferences dev->p. device_add() freed dev->p on its error path, so this
is a NULL dereference:
Oops: general protection fault, probably for non-canonical address ...
KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f]
RIP: 0010:__device_attach+0xb0/0x4d0
Call Trace:
device_initial_probe+0xaf/0xd0
pci_bus_add_device+0xc5/0x100
pci_bus_add_devices+0x9a/0x1f0
pci_rescan_bus+0x2a/0x40
rescan_store+0xfb/0x130
Kernel panic - not syncing: Fatal exception
Propagate the error instead. pci_setup_device() already returns int and
both callers, pci_scan_device() and pci_iov_scan_device(), release the
device on failure, so no caller changes are needed. Release the OF node
first, matching the existing error path for an unknown header type.
Reported-by: syzbot+87bb32e345aa80c0554b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=87bb32e345aa80c0554b
Fixes: eebfcfb52ce7 ("PCI: handle pci_name() being const")
Signed-off-by: Rihyeon Kim <rihyeon8648@gmail.com>
---
drivers/pci/probe.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c
index dd0abbc63e18..474c6cb327be 100644
--- a/drivers/pci/probe.c
+++ b/drivers/pci/probe.c
@@ -2052,9 +2052,13 @@ int pci_setup_device(struct pci_dev *dev)
*/
dev->msi_addr_mask = DMA_BIT_MASK(64);
- dev_set_name(&dev->dev, "%04x:%02x:%02x.%d", pci_domain_nr(dev->bus),
- dev->bus->number, PCI_SLOT(dev->devfn),
- PCI_FUNC(dev->devfn));
+ err = dev_set_name(&dev->dev, "%04x:%02x:%02x.%d",
+ pci_domain_nr(dev->bus), dev->bus->number,
+ PCI_SLOT(dev->devfn), PCI_FUNC(dev->devfn));
+ if (err) {
+ pci_release_of_node(dev);
+ return err;
+ }
class = pci_class(dev);
--
2.43.0
prev parent reply other threads:[~2026-07-25 10:06 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-21 0:08 [syzbot] [pci?] WARNING in pci_scan_single_device (2) syzbot
2026-07-24 22:31 ` syzbot
2026-07-25 10:06 ` syzbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a648aba.073198cf.94f0f.0013.GAE@google.com \
--to=syzbot+87bb32e345aa80c0554b@syzkaller.appspotmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.