Skip to content

Commit 56f7db5

Browse files
ryanlin0317Jiri Kosina
authored andcommitted
HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
During a warm reset flow, the cl->device pointer may be NULL if the reset occurs while clients are still being enumerated. Accessing cl->device->reference_count without a NULL check leads to a kernel panic. This issue was identified during multi-unit warm reboot stress clycles. Add a defensive NULL check for cl->device to ensure stability under such intensive testing conditions. KASAN: null-ptr-deref in range [0000000000000000-0000000000000007] Workqueue: ish_fw_update_wq fw_reset_work_fn Call Trace: ishtp_bus_remove_all_clients+0xbe/0x130 [intel_ishtp] ishtp_reset_handler+0x85/0x1a0 [intel_ishtp] fw_reset_work_fn+0x8a/0xc0 [intel_ish_ipc] Fixes: 3703f53 ("HID: intel_ish-hid: ISH Transport layer") Signed-off-by: Ryan Lin <ryan.lin@intel.com> Signed-off-by: Jiri Kosina <jkosina@suse.com>
1 parent af4fe07 commit 56f7db5

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

  • drivers/hid/intel-ish-hid/ishtp

drivers/hid/intel-ish-hid/ishtp/bus.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -730,7 +730,7 @@ void ishtp_bus_remove_all_clients(struct ishtp_device *ishtp_dev,
730730
spin_lock_irqsave(&ishtp_dev->cl_list_lock, flags);
731731
list_for_each_entry(cl, &ishtp_dev->cl_list, link) {
732732
cl->state = ISHTP_CL_DISCONNECTED;
733-
if (warm_reset && cl->device->reference_count)
733+
if (warm_reset && cl->device && cl->device->reference_count)
734734
continue;
735735

736736
/*

0 commit comments

Comments
 (0)