]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
hwmon: (lm90) Only report alarms if driver is ready
authorGuenter Roeck <linux@roeck-us.net>
Sat, 25 Jul 2026 22:27:28 +0000 (15:27 -0700)
committerGuenter Roeck <linux@roeck-us.net>
Mon, 27 Jul 2026 18:35:22 +0000 (11:35 -0700)
Userspace can read sysfs attributes before driver registration is complete,
immediately after devm_hwmon_device_register_with_info() has been called.
At that time, data->hwmon_dev is not yet initialized. This can trigger
a NULL pointer access since lm90_update_device() and with it
lm90_update_alarms_locked() will be called. This call schedules
report_work and lm90_report_alarms(), which passes the still-NULL
data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer
dereference.

Fix the problem by only scheduling the report and alert workers
data->hwmon_dev is set.

Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: f6d0775119fb9 ("hwmon: (lm90) Rework alarm/status handling")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
drivers/hwmon/lm90.c

index 4b9c0ccdf2609fab88a6610e8a30c1ecd8516aac..c6186505661ff165ae04aa8994d84724b4ac97f7 100644 (file)
@@ -1194,7 +1194,7 @@ static int lm90_update_alarms_locked(struct lm90_data *data, bool force)
                check_enable = (client->irq || !(data->config_orig & 0x80)) &&
                        (data->config & 0x80);
 
-               if (force || check_enable)
+               if (data->hwmon_dev && (force || check_enable))
                        schedule_work(&data->report_work);
 
                /*
@@ -1202,7 +1202,7 @@ static int lm90_update_alarms_locked(struct lm90_data *data, bool force)
                 * alarms are all clear, and alerts are currently disabled.
                 * Otherwise (re)schedule worker if needed.
                 */
-               if (check_enable) {
+               if (check_enable && data->hwmon_dev) {
                        if (!(data->current_alarms & data->alert_alarms)) {
                                dev_dbg(&client->dev, "Re-enabling ALERT#\n");
                                lm90_update_confreg(data, data->config & ~0x80);