From: Christoph Winklhofer <cj.winklhofer@gmail.com>
To: Chenyuan Yang <chenyuan0y@gmail.com>
Cc: krzk@kernel.org, linux-kernel@vger.kernel.org, zijie98@gmail.com
Subject: Re: [PATCH] w1: fix NULL pointer dereference in probe
Date: Sat, 18 Jan 2025 14:15:37 +0100 [thread overview]
Message-ID: <Z4upeb9_AvUpE6xS@cjw-notebook> (raw)
In-Reply-To: <20250111181803.2283611-1-chenyuan0y@gmail.com>
On Sat, Jan 11, 2025 at 12:18:03PM -0600, Chenyuan Yang wrote:
> The w1_uart_probe() function calls w1_uart_serdev_open() (which includes
> devm_serdev_device_open()) before setting the client ops via
> serdev_device_set_client_ops(). This ordering can trigger a NULL pointer
> dereference in the serdev controller's receive_buf handler, as it assumes
> serdev->ops is valid when SERPORT_ACTIVE is set.
>
> This is similar to the issue fixed in commit 5e700b384ec1
> ("platform/chrome: cros_ec_uart: properly fix race condition") where
> devm_serdev_device_open() was called before fully initializing the
> device.
>
> Fix the race by ensuring client ops are set before enabling the port via
> w1_uart_serdev_open().
>
> Fixes: a3c08804364e ("w1: add UART w1 bus driver")
> Signed-off-by: Chenyuan Yang <chenyuan0y@gmail.com>
> ---
> drivers/w1/masters/w1-uart.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
Acked-by: Christoph Winklhofer <cj.winklhofer@gmail.com>
Thanks for the fix!
I tested it with a Raspberry PI and DS18B20 sensor.
Best,
Christoph
next prev parent reply other threads:[~2025-01-18 13:15 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-01-11 18:18 [PATCH] w1: fix NULL pointer dereference in probe Chenyuan Yang
2025-01-18 13:15 ` Christoph Winklhofer [this message]
2025-02-03 11:54 ` Krzysztof Kozlowski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Z4upeb9_AvUpE6xS@cjw-notebook \
--to=cj.winklhofer@gmail.com \
--cc=chenyuan0y@gmail.com \
--cc=krzk@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=zijie98@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.