]> git.ipfire.org Git - thirdparty/linux.git/commit
hwmon: (lm90) Only report alarms if driver is ready
authorGuenter Roeck <linux@roeck-us.net>
Sat, 25 Jul 2026 22:27:28 +0000 (15:27 -0700)
committerGuenter Roeck <linux@roeck-us.net>
Mon, 27 Jul 2026 18:35:22 +0000 (11:35 -0700)
commitaa9429edf9fc0e90d6f4da19ea4b5495a54ab117
treec65c56b2d14b84dd1f1abc3c3ceb5a758ef5fe0d
parentf46d5ab43a572b84773015a76966f5da56fc1748
hwmon: (lm90) Only report alarms if driver is ready

Userspace can read sysfs attributes before driver registration is complete,
immediately after devm_hwmon_device_register_with_info() has been called.
At that time, data->hwmon_dev is not yet initialized. This can trigger
a NULL pointer access since lm90_update_device() and with it
lm90_update_alarms_locked() will be called. This call schedules
report_work and lm90_report_alarms(), which passes the still-NULL
data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer
dereference.

Fix the problem by only scheduling the report and alert workers
data->hwmon_dev is set.

Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: f6d0775119fb9 ("hwmon: (lm90) Rework alarm/status handling")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
drivers/hwmon/lm90.c