[PATCH 7/9] iio: adc: ti-ads1018: reject devices without match data
From: Jiale Yao
Date: Fri Sep 25 2026 - 09:02:58 EST
SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.
ads1018_spi_probe() immediately dereferences the returned chip
information to initialize the IIO device, causing a NULL pointer
dereference.
Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data before allocating the IIO device.
Fixes: bf0bba486b5b ("iio: adc: Add ti-ads1018 driver")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/iio/adc/ti-ads1018.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/iio/adc/ti-ads1018.c b/drivers/iio/adc/ti-ads1018.c
index d9ec4a8d7ce5..8f2d03eee77b 100644
--- a/drivers/iio/adc/ti-ads1018.c
+++ b/drivers/iio/adc/ti-ads1018.c
@@ -624,12 +624,16 @@ static int ads1018_trigger_setup(struct iio_dev *indio_dev)
static int ads1018_spi_probe(struct spi_device *spi)
{
- const struct ads1018_chip_info *info = spi_get_device_match_data(spi);
+ const struct ads1018_chip_info *info;
struct device *dev = &spi->dev;
struct iio_dev *indio_dev;
struct ads1018 *ads1018;
int ret;
+ info = spi_get_device_match_data(spi);
+ if (!info)
+ return -ENODATA;
+
indio_dev = devm_iio_device_alloc(dev, sizeof(*ads1018));
if (!indio_dev)
return -ENOMEM;
--
2.34.1