mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf()
@ 2026-10-09  6:18 Haotian Zhang
  2026-10-09  9:41 ` Krzysztof Kozlowski
  0 siblings, 1 reply; 2+ messages in thread
From: Haotian Zhang @ 2026-10-09  6:18 UTC (permalink / raw)
  To: Stephen Boyd, Brian Masney, Jerome Brunet, Michal Simek, Michael Tretter
  Cc: linux-clk, linux-arm-kernel, linux-kernel

xvcu_clk_hw_unregister_leaf() gets the mux with
clk_hw_get_parent(divider), which returns NULL when the divider has no
parent, and passes it to clk_hw_unregister_mux() without checking it.
The following check tests the wrong variable: divider has already been
verified to be non-NULL at this point, so "if (!divider) return;" is
dead code and a NULL mux is dereferenced, crashing in
clk_hw_unregister_mux().

Only unregister the mux when it is non-NULL, and always release the
divider.

Fixes: 9c789deea206 ("soc: xilinx: vcu: implement clock provider for output clocks")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
 drivers/clk/xilinx/xlnx_vcu.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/clk/xilinx/xlnx_vcu.c b/drivers/clk/xilinx/xlnx_vcu.c
index f14bda375e35..b004c16692d3 100644
--- a/drivers/clk/xilinx/xlnx_vcu.c
+++ b/drivers/clk/xilinx/xlnx_vcu.c
@@ -516,9 +516,8 @@ static void xvcu_clk_hw_unregister_leaf(struct clk_hw *hw)
 		return;
 
 	mux = clk_hw_get_parent(divider);
-	clk_hw_unregister_mux(mux);
-	if (!divider)
-		return;
+	if (mux)
+		clk_hw_unregister_mux(mux);
 
 	clk_hw_unregister_divider(divider);
 }
-- 
2.25.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf()
  2026-10-09  6:18 [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf() Haotian Zhang
@ 2026-10-09  9:41 ` Krzysztof Kozlowski
  0 siblings, 0 replies; 2+ messages in thread
From: Krzysztof Kozlowski @ 2026-10-09  9:41 UTC (permalink / raw)
  To: Haotian Zhang, Stephen Boyd, Brian Masney, Jerome Brunet,
	Michal Simek, Michael Tretter
  Cc: linux-clk, linux-arm-kernel, linux-kernel

On 09/10/2026 08:18, Haotian Zhang wrote:
> xvcu_clk_hw_unregister_leaf() gets the mux with
> clk_hw_get_parent(divider), which returns NULL when the divider has no
> parent, and passes it to clk_hw_unregister_mux() without checking it.
> The following check tests the wrong variable: divider has already been
> verified to be non-NULL at this point, so "if (!divider) return;" is
> dead code and a NULL mux is dereferenced, crashing in
> clk_hw_unregister_mux().
> 
> Only unregister the mux when it is non-NULL, and always release the
> divider.

So you fired up your OpenClaw or whatever LLM tool and don't bother to
slow down, right?

Best regards,
Krzysztof

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-09  9:41 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09  6:18 [PATCH] clk: xilinx: fix NULL pointer dereference in xvcu_clk_hw_unregister_leaf() Haotian Zhang
2026-10-09  9:41 ` Krzysztof Kozlowski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®