Re: [PATCH 2/2] mailbox: qcom-cpucp: handle NULL data in send_data callback

From: Dmitry Baryshkov

Date: Tue Aug 11 2026 - 09:04:55 EST


On Thu, Aug 06, 2026 at 03:03:57PM +0800, Jia Yang wrote:
> mailbox_clear_channel() calls mbox_send_message() with NULL data to
> notify the remote side that the RX channel has been cleared.
> qcom_cpucp_mbox_send_data() blindly dereferenced the data pointer,
> causing a NULL pointer dereference kernel panic when invoked from
> this path under PREEMPT_RT.
>
> Add an explicit NULL check and return early without writing to the
> TX register, which is the correct behaviour for a channel-clear
> notification.
>
> Fixes: 0e2a9a03106c ("mailbox: Add support for QTI CPUCP mailbox controller")
> Signed-off-by: Jia Yang <jia.yang@xxxxxxxxxxxxxxxx>
> ---
> drivers/mailbox/qcom-cpucp-mbox.c | 8 ++++++++
> 1 file changed, 8 insertions(+)
>

Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@xxxxxxxxxxxxxxxx>


--
With best wishes
Dmitry