All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jarkko Sakkinen <jarkko.sakkinen@iki.fi>
To: Pei Xiao <xiaopei01@kylinos.cn>
Cc: jarkko@kernel.org, peterhuewe@gmx.de, jgg@ziepe.ca,
	linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 2/5] tpm: tpm_nsc: fix NULL pointer dereference on init failure
Date: Mon, 5 Oct 2026 07:18:28 +0300	[thread overview]
Message-ID: <asMlFHPxPuR7IlXL@iki.fi> (raw)
In-Reply-To: <d5f0b38d6d6c17c01519c879d26448dbae388b0e.1791015549.git.xiaopei01@kylinos.cn>

On Sat, Oct 03, 2026 at 04:27:52PM +0800, Pei Xiao wrote:
> tpm_nsc_remove() is used as the release callback of the hand-created
> platform device and dereferences the chip drvdata unconditionally.
> If init fails before tpmm_chip_alloc() (e.g. request_region() cannot
> claim the ports), the error path drops the last device reference and
> the release callback runs with chip == NULL, crashing module init.
> 
> Return early when the chip has not been created yet.
> 
> Fixes: afb5abc262e9 ("tpm: two-phase chip management functions")
> Assisted-by: GLM-5.3
> Signed-off-by: Pei Xiao <xiaopei01@kylinos.cn>
> ---
>  drivers/char/tpm/tpm_nsc.c | 7 ++++++-
>  1 file changed, 6 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/char/tpm/tpm_nsc.c b/drivers/char/tpm/tpm_nsc.c
> index 879ac88f5783..46a52dc99b14 100644
> --- a/drivers/char/tpm/tpm_nsc.c
> +++ b/drivers/char/tpm/tpm_nsc.c
> @@ -259,7 +259,12 @@ static struct platform_device *pdev = NULL;
>  static void tpm_nsc_remove(struct device *dev)
>  {
>  	struct tpm_chip *chip = dev_get_drvdata(dev);
> -	struct tpm_nsc_priv *priv = dev_get_drvdata(&chip->dev);
> +	struct tpm_nsc_priv *priv;
> +
> +	if (!chip)
> +		return;
> +
> +	priv = dev_get_drvdata(&chip->dev);
>  
>  	tpm_chip_unregister(chip);
>  	release_region(priv->base, 2);
> -- 
> 2.25.1
> 

I can apply this, thanks.

Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>

Br, Jarkko

  reply	other threads:[~2026-10-05  4:18 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03  8:27 [PATCH 0/5] tpm: assorted fixes and cleanups Pei Xiao
2026-10-03  8:27 ` [PATCH 1/5] tpm: tpm_ppi: fix wrong error code returned to user space Pei Xiao
2026-10-05  4:16   ` Jarkko Sakkinen
2026-10-05  6:17     ` Pei Xiao
2026-10-05  7:42       ` Jarkko Sakkinen
2026-10-03  8:27 ` [PATCH 2/5] tpm: tpm_nsc: fix NULL pointer dereference on init failure Pei Xiao
2026-10-05  4:18   ` Jarkko Sakkinen [this message]
2026-10-03  8:27 ` [PATCH 3/5] tpm: tpm_nsc: stop using the cleanup callback as dev.release Pei Xiao
2026-10-05  4:19   ` Jarkko Sakkinen
2026-10-03  8:27 ` [PATCH 4/5] tpm: fix zero-length read discarding the pending response Pei Xiao
2026-10-05  5:11   ` Jarkko Sakkinen
2026-10-03  8:27 ` [PATCH 5/5] tpm: fix log messages in tpm_init() Pei Xiao
2026-10-05  3:46   ` Jarkko Sakkinen
2026-10-05  4:23     ` Pei Xiao
2026-10-05  6:05       ` Jarkko Sakkinen
2026-10-05  6:10         ` Pei Xiao
2026-10-05  6:11         ` Jarkko Sakkinen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=asMlFHPxPuR7IlXL@iki.fi \
    --to=jarkko.sakkinen@iki.fi \
    --cc=jarkko@kernel.org \
    --cc=jgg@ziepe.ca \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=peterhuewe@gmx.de \
    --cc=xiaopei01@kylinos.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.