From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 126761EA84 for ; Wed, 6 May 2026 19:05:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778094350; cv=none; b=axAfQxH63CdbOjAyJ80j4FA/ZpI80N85MGqbeKZKZ2xVd4GTLnPb+mawXkmhfvfa+9Tud9dBlvKqg7syVGlaiVp36XVzbG49tkwCak/Hg3uWKyywG1SWzU+bvQoftn6lV5X/AgDg2uOEn6vVdYVvTSA1TrooTBFoLt7ywR44oC0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778094350; c=relaxed/simple; bh=aV7/ddYd8n/VEWp8goC8zoqNFJsPEIXQ1fyZbpIE3MU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=FkHg3LOSl3S6CxrVgv8fNgNEs7USvFY180xFjWVdbSuDrlQb6cMxihzOsYVnyk1d4+cZY6WTxg1Pac/+jikWHIkpWLWKzXtvkl/aznRDwPHiREbYFVNLWUbdnez84lMt5FH9nFEiqYfRLXnAv7CMsrVoKn/TmjNKjySeU3owWxk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gWKu5o3R; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gWKu5o3R" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-488ac04e13dso39295e9.1 for ; Wed, 06 May 2026 12:05:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1778094346; x=1778699146; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=RWaGVwrz8dpWHB2wk2T9j8VY/b7+3Y4aZTgZzUxXD1Y=; b=gWKu5o3RyOAmPwD0Itg6JX/2tmc6Oyg8pNotuXzEjqnZgvJDPAwjmI430xHYDyeTv4 W7DmYA3UpPUYxk/XVgwhRda8X8DQ1G4eqIaMUZMXn8DrSICvSS4BbDBwxma4h4KiYjfj id9VCj5qcf1pY5J8PeMZycuItc8vVaMNtEUCphPzVpZWEPstyzrK02QpBlseWIFkccbK eZuuZBoI2pTcxCt2o6D48k/4gmjkfXNo/1iXYxMqY/jDq05kjmPCizFwSwBCeGJMaCxo ZSE6D8hR0mB2ME1QPpmIRpOr/INtREV7sR/7cBgXRGzxKZEvPrdhnQTAmodvSIeKK801 HS4w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1778094346; x=1778699146; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=RWaGVwrz8dpWHB2wk2T9j8VY/b7+3Y4aZTgZzUxXD1Y=; b=XrMp/cJ6qnuW0evQgQapSJmsCdoKL97w064QR8BuLJ7mSHT27rYyik4CMpGi/Iybaw 6i41udoMWvHprM5Dfa53/tPRAPnlWTxsX/pm7sVhPgpYHuC3TS4HdDftsSAWnd1fzQX6 pFkYHJkkK5MyhMTQ33rnn9NMWmcjcgHJPXmx3QP4R+n99gpn/gXHk+MMkFNT5bFE6X3+ lT3bZ6PVgmzavO9W8GOk7mZHkaHM+nD+2FmvBSTFJtT4fFjBVFs9oVuSb/G9M0ELuQ8c 5dOxjqsK8qjdtxrUhpWgbvcJknSZB0zsgsuTV3nti6CnzPJJfBynxytaWWnBngGnWihN NBdw== X-Forwarded-Encrypted: i=1; AFNElJ84ntZnHQj/kioCXff08odetZodNsbvhEKa1ITxJsqbqRkDuOpSqB/dSW7zTDE8AcDpFfSvTLn9l0FsXMs=@vger.kernel.org X-Gm-Message-State: AOJu0YwXTrckF0oxKCJ73tle4TRjSN1HSW1JLAYREe1SLZqoeqU7oqQs mkXE6JXxwkDSEDnrb/5TfweV4qsvHgkrmMNJ6SA2tX9yrEjnNyRFy6H/n8Ql1TKCf0YWFA== X-Gm-Gg: AeBDiesmnDARqKohhihMRC+YhaUS9/mBff8ju71LbMo7EjMn+kBsrB4mqTf+Zb1Je4X Vo0amMoQ4i1c6zIw57++7nwELASLeDayOpDBbHk6MdkvwljyLXrzyMVsRSRbguFJe+Pwu2eTRiT +TQ+RG2Ao7sHIxwaq4h2sF3jQFT5tW8r7o+ioTdWrEif1CHSqMHOcRWODuwPknu8UpUaN99/F/r M3pk9Bg7eUXwmNQMEKb4yzhe0zWabpOe5Z2CYtdKKMR016rB+I59ZzodJUXoghT3BUvOGsalcdv /h2TxDaT8/1bZtvLtvBJlAbI5hMC7vDVcexOf25t+Lwa82QNJCjClW2XumoHS1I4ftTXKEjvue/ ayGznXQs7hLdUbrCoSzS5UUDwnQwrkoFzWoAWtZMaUlxZTgDnIP1DVzx+mPndxsBQNFo7x3Q3Va v6UlQmqPUrxFvIxzz5RuMIy4sI6KEaSfyE0Por/qqwvvT8V+8tNszC X-Received: by 2002:a05:600c:4588:b0:48a:5302:8ed9 with SMTP id 5b1f17b1804b1-48e52f1574emr36086805e9.0.1778094346183; Wed, 06 May 2026 12:05:46 -0700 (PDT) Received: from LAPTOP-9UC0RPH4.localdomain ([82.215.118.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-48e530b212esm30832605e9.1.2026.05.06.12.05.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 06 May 2026 12:05:45 -0700 (PDT) From: Stepan Ionichev To: ulfh@kernel.org Cc: brgl@kernel.org, linux-mmc@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Stepan Ionichev Subject: [PATCH] mmc: davinci: avoid NULL deref of host->data in IRQ handler Date: Thu, 7 May 2026 00:05:37 +0500 Message-ID: <20260506190538.596-1-sozdayvek@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit mmc_davinci_irq() returns early only when both host->cmd and host->data are NULL: if (host->cmd == NULL && host->data == NULL) { ... return IRQ_NONE; } So we may legitimately reach the rest of the handler with host->data == NULL (and therefore data == NULL). The DATDNE branch already guards against this with an explicit "if (data != NULL)" check, but the subsequent TOUTRD ("read data timeout") and CRCWR/CRCRD ("data CRC error") branches dereference data unconditionally: if (qstatus & MMCST0_TOUTRD) { data->error = -ETIMEDOUT; <-- NULL deref ... davinci_abort_data(host, data); } if (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD)) { data->error = -EILSEQ; <-- NULL deref ... } If either bit is set in qstatus while host->data is NULL, the kernel will crash inside the IRQ handler. smatch flags this: drivers/mmc/host/davinci_mmc.c:933 mmc_davinci_irq() error: we previously assumed 'data' could be null (see line 914) Gate both branches on a non-NULL data, matching the existing pattern used by the DATDNE branch. No functional change for callers where data is non-NULL, which is the only case in which these branches did meaningful work before this change. Signed-off-by: Stepan Ionichev --- drivers/mmc/host/davinci_mmc.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/mmc/host/davinci_mmc.c b/drivers/mmc/host/davinci_mmc.c index 42b0118a4..42ad87aa4 100644 --- a/drivers/mmc/host/davinci_mmc.c +++ b/drivers/mmc/host/davinci_mmc.c @@ -928,7 +928,7 @@ static irqreturn_t mmc_davinci_irq(int irq, void *dev_id) } } - if (qstatus & MMCST0_TOUTRD) { + if (data && (qstatus & MMCST0_TOUTRD)) { /* Read data timeout */ data->error = -ETIMEDOUT; end_transfer = 1; @@ -940,7 +940,7 @@ static irqreturn_t mmc_davinci_irq(int irq, void *dev_id) davinci_abort_data(host, data); } - if (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD)) { + if (data && (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD))) { /* Data CRC error */ data->error = -EILSEQ; end_transfer = 1; -- 2.43.0