Skip to content

Commit 4529456

Browse files
rafaeljwgregkh
authored andcommitted
ACPI: NFIT: core: Fix possible NULL pointer dereference
commit 027e128 upstream. After commit 9b311b7 ("ACPI: NFIT: Install Notify() handler before getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler for the NFIT device before checking the presence of the NFIT table. If that table is not there, 0 is returned without allocating the acpi_desc object and setting the driver data pointer of the NFIT device. If the platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification on the NFIT device at that point, acpi_nfit_uc_error_notify() will dereference a NULL pointer. Prevent that from occurring by adding an acpi_desc check against NULL to acpi_nfit_uc_error_notify(). Fixes: 9b311b7 ("ACPI: NFIT: Install Notify() handler before getting NFIT table") Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com> Cc: All applicable <stable@vger.kernel.org> Reviewed-by: Dave Jiang <dave.jiang@intel.com> Link: https://patch.msgid.link/2418508.ElGaqSPkdT@rafael.j.wysocki Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent f29dc61 commit 4529456

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

drivers/acpi/nfit/core.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3447,6 +3447,9 @@ static void acpi_nfit_uc_error_notify(struct device *dev, acpi_handle handle)
34473447
{
34483448
struct acpi_nfit_desc *acpi_desc = dev_get_drvdata(dev);
34493449

3450+
if (!acpi_desc)
3451+
return;
3452+
34503453
if (acpi_desc->scrub_mode == HW_ERROR_SCRUB_ON)
34513454
acpi_nfit_ars_rescan(acpi_desc, ARS_REQ_LONG);
34523455
else

0 commit comments

Comments
 (0)