]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
iommu: Fix NULL group->domain dereference in pci_dev_reset_iommu_done()
authorNicolin Chen <nicolinc@nvidia.com>
Sat, 25 Apr 2026 01:15:20 +0000 (18:15 -0700)
committerJoerg Roedel <joerg.roedel@amd.com>
Mon, 11 May 2026 08:12:43 +0000 (10:12 +0200)
commitd769711fcddd005f1e654b3bde547140917fe696
treee114c98b6d143382c1fc980229622590cfbdd9b2
parent07d0f496fe7ec5abe3bee7e38be709521567bb33
iommu: Fix NULL group->domain dereference in pci_dev_reset_iommu_done()

Local sashiko review pointed it out that group->domain could be NULL when
a default domain fails to allocate during the first probe, which can crash
at domain->ops->attach_dev dereference in __iommu_attach_device() invoked
by pci_dev_reset_iommu_done().

pci_dev_reset_iommu_prepare() is fine as an old_domain pointer can be NULL.

Skip the re-attach in pci_dev_reset_iommu_done() to fix the bug.

Fixes: c279e83953d9 ("iommu: Introduce pci_dev_reset_iommu_prepare/done()")
Cc: stable@vger.kernel.org
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Reviewed-by: Lu Baolu <baolu.lu@linux.intel.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
drivers/iommu/iommu.c