Re: [PATCH] ACPI: SBS: Fix NULL pointer dereference on allocation failure

From: Rafael J. Wysocki (Intel)

Date: Mon Sep 14 2026 - 14:10:51 EST


On Sat, Sep 12, 2026 at 1:34 PM Guangshuo Li <lgs201920130244@xxxxxxxxx> wrote:
>
> acpi_sbs_probe() jumps to the common error path when kzalloc_obj()
> fails, but platform_set_drvdata() is only called after the allocation
> succeeds.
>
> The error path calls acpi_sbs_remove(), which retrieves the unset
> driver data and dereferences the resulting NULL pointer when locking
> sbs->lock, causing a NULL pointer dereference.
>
> Return -ENOMEM directly when the allocation fails, since no resources
> have been initialized at that point and there is nothing to clean up.
>
> This issue was found by manual code inspection.
>
> Fixes: 9460eaae2ee42 ("ACPI: SBS: Convert the driver to a platform one")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Guangshuo Li <lgs201920130244@xxxxxxxxx>
> ---
> drivers/acpi/sbs.c | 6 ++----
> 1 file changed, 2 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/acpi/sbs.c b/drivers/acpi/sbs.c
> index 86b7c7975852..4b84b3cd11e3 100644
> --- a/drivers/acpi/sbs.c
> +++ b/drivers/acpi/sbs.c
> @@ -639,10 +639,8 @@ static int acpi_sbs_probe(struct platform_device *pdev)
> return -ENODEV;
>
> sbs = kzalloc_obj(struct acpi_sbs);
> - if (!sbs) {
> - result = -ENOMEM;
> - goto end;
> - }
> + if (!sbs)
> + return -ENOMEM;
>
> mutex_init(&sbs->lock);
>
> --

Applied as 7.4 material, thanks!