* [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf()
@ 2026-10-09 6:18 Haotian Zhang
2026-10-09 9:41 ` Krzysztof Kozlowski
0 siblings, 1 reply; 2+ messages in thread
From: Haotian Zhang @ 2026-10-09 6:18 UTC (permalink / raw)
To: Stephen Boyd, Brian Masney, Jerome Brunet, Michal Simek,
Michael Tretter
Cc: linux-clk, linux-arm-kernel, linux-kernel
xvcu_clk_hw_unregister_leaf() gets the mux with
clk_hw_get_parent(divider), which returns NULL when the divider has no
parent, and passes it to clk_hw_unregister_mux() without checking it.
The following check tests the wrong variable: divider has already been
verified to be non-NULL at this point, so "if (!divider) return;" is
dead code and a NULL mux is dereferenced, crashing in
clk_hw_unregister_mux().
Only unregister the mux when it is non-NULL, and always release the
divider.
Fixes: 9c789deea206 ("soc: xilinx: vcu: implement clock provider for output clocks")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
drivers/clk/xilinx/xlnx_vcu.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/clk/xilinx/xlnx_vcu.c b/drivers/clk/xilinx/xlnx_vcu.c
index f14bda375e35..b004c16692d3 100644
--- a/drivers/clk/xilinx/xlnx_vcu.c
+++ b/drivers/clk/xilinx/xlnx_vcu.c
@@ -516,9 +516,8 @@ static void xvcu_clk_hw_unregister_leaf(struct clk_hw *hw)
return;
mux = clk_hw_get_parent(divider);
- clk_hw_unregister_mux(mux);
- if (!divider)
- return;
+ if (mux)
+ clk_hw_unregister_mux(mux);
clk_hw_unregister_divider(divider);
}
--
2.25.1
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf()
2026-10-09 6:18 [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf() Haotian Zhang
@ 2026-10-09 9:41 ` Krzysztof Kozlowski
0 siblings, 0 replies; 2+ messages in thread
From: Krzysztof Kozlowski @ 2026-10-09 9:41 UTC (permalink / raw)
To: Haotian Zhang, Stephen Boyd, Brian Masney, Jerome Brunet,
Michal Simek, Michael Tretter
Cc: linux-clk, linux-arm-kernel, linux-kernel
On 09/10/2026 08:18, Haotian Zhang wrote:
> xvcu_clk_hw_unregister_leaf() gets the mux with
> clk_hw_get_parent(divider), which returns NULL when the divider has no
> parent, and passes it to clk_hw_unregister_mux() without checking it.
> The following check tests the wrong variable: divider has already been
> verified to be non-NULL at this point, so "if (!divider) return;" is
> dead code and a NULL mux is dereferenced, crashing in
> clk_hw_unregister_mux().
>
> Only unregister the mux when it is non-NULL, and always release the
> divider.
So you fired up your OpenClaw or whatever LLM tool and don't bother to
slow down, right?
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-09 9:41 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-09 6:18 [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf() Haotian Zhang
2026-10-09 9:41 ` Krzysztof Kozlowski
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox