[PATCH] of/address: Fix NULL bus dereference in of_pci_range_parser_one()

From: Carlo Caione

Date: Mon Jul 06 2026 - 06:56:57 EST


The bus matching rework made of_match_bus() return NULL for nodes
with ranges/dma-ranges but no local #address-cells. parser_init()
stored that NULL bus, and the range iterator later dereferenced it.

Reject such nodes in parser_init(), leaving an explicit empty iterator
for callers that ignore the init return. Keep the DMA limit walk guarded
by a non-empty dma-ranges property, and only clamp the limit when at
least one complete range was parsed.

Fixes: 64ee3cf096ac ("of/address: Rework bus matching to avoid warnings")
Signed-off-by: Carlo Caione <ccaione@xxxxxxxxxxxx>
---
drivers/of/address.c | 21 +++++++++++++++------
1 file changed, 15 insertions(+), 6 deletions(-)

diff --git a/drivers/of/address.c b/drivers/of/address.c
index cf4aab11e9b1..b57b1adbad44 100644
--- a/drivers/of/address.c
+++ b/drivers/of/address.c
@@ -753,6 +753,7 @@ EXPORT_SYMBOL(of_property_read_reg);
static int parser_init(struct of_pci_range_parser *parser,
struct device_node *node, const char *name)
{
+ const __be32 *range;
int rlen;

parser->node = node;
@@ -761,12 +762,18 @@ static int parser_init(struct of_pci_range_parser *parser,
parser->ns = of_bus_n_size_cells(node);
parser->dma = !strcmp(name, "dma-ranges");
parser->bus = of_match_bus(node);
+ parser->range = NULL;
+ parser->end = NULL;

- parser->range = of_get_property(node, name, &rlen);
- if (parser->range == NULL)
+ range = of_get_property(node, name, &rlen);
+ if (!range)
return -ENOENT;

- parser->end = parser->range + rlen / sizeof(__be32);
+ if (!parser->bus)
+ return -EINVAL;
+
+ parser->range = range;
+ parser->end = range + rlen / sizeof(__be32);

return 0;
}
@@ -792,7 +799,7 @@ struct of_pci_range *of_pci_range_parser_one(struct of_pci_range_parser *parser,
int na = parser->na;
int ns = parser->ns;
int np = parser->pna + na + ns;
- int busflag_na = parser->bus->flag_cells;
+ int busflag_na;

if (!range)
return NULL;
@@ -800,6 +807,8 @@ struct of_pci_range *of_pci_range_parser_one(struct of_pci_range_parser *parser,
if (!parser->range || parser->range + np > parser->end)
return NULL;

+ busflag_na = parser->bus->flag_cells;
+
range->flags = parser->bus->get_flags(parser->range);

range->bus_addr = of_read_number(parser->range + busflag_na, na - busflag_na);
@@ -976,8 +985,8 @@ phys_addr_t __init of_dma_get_max_cpu_address(struct device_node *np)
np = of_root;

ranges = of_get_property(np, "dma-ranges", &len);
- if (ranges && len) {
- of_dma_range_parser_init(&parser, np);
+ if (ranges && len && !of_dma_range_parser_init(&parser, np) &&
+ of_range_count(&parser)) {
for_each_of_range(&parser, &range)
if (range.cpu_addr + range.size > cpu_end)
cpu_end = range.cpu_addr + range.size - 1;
--
2.55.0