[PATCH 5/6] fbdev: smscufx: check for fb_deferred_io_init() error
From: Lorenzo Stoakes (ARM)
Date: Sat Sep 26 2026 - 09:28:01 EST
fb_deferred_io_init() allocates deferred I/O state, populating
info->fbdefio_state, or leaving it NULL if an error occurs.
Currently ufx_ops_open() ignores its return value.
Therefore if an error arises in fb_deferred_io_init() (for instance, due to
an allocation failure) info->fbdefio_state is left NULL.
fb_open() will then dereference a NULL pointer (calling
fb_deferred_io_open()) as soon as ufx_ops_open() returns.
Additionally, if the allocation of info->fbdefio itself fails,
ufx_ops_open() sets info->fbdefio to NULL and invokes
fb_deferred_io_init() regardless, hitting BUG_ON(!fbdefio).
Fix this by only invoking fb_deferred_io_init() if the allocation
succeeded, and checking for the error.
The driver already supports operating without deferred I/O, so in either
case fall back to that by setting info->fbdefio to NULL.
The ignored return value was introduced in commit 56c134f7f1b5 ("fbdev:
Track deferred-I/O pages in pageref struct").
However, the BUG_ON() issue originates from the earlier
commit 3c8a63e22a08 ("Add support for SMSC UFX6000/7000 USB display
adapters"), so target that for the fix.
Fixes: 3c8a63e22a08 ("Add support for SMSC UFX6000/7000 USB display adapters")
Cc: <stable@xxxxxxxxxxxxxxx>
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@xxxxxxxxxx>
---
drivers/video/fbdev/smscufx.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/video/fbdev/smscufx.c b/drivers/video/fbdev/smscufx.c
index 5704f60e1741..34d8abd5b354 100644
--- a/drivers/video/fbdev/smscufx.c
+++ b/drivers/video/fbdev/smscufx.c
@@ -1041,10 +1041,13 @@ static int ufx_ops_open(struct fb_info *info, int user)
if (fbdefio) {
fbdefio->delay = UFX_DEFIO_WRITE_DELAY;
fbdefio->deferred_io = ufx_dpy_deferred_io;
- }
- info->fbdefio = fbdefio;
- fb_deferred_io_init(info);
+ info->fbdefio = fbdefio;
+ if (fb_deferred_io_init(info)) {
+ kfree(fbdefio);
+ info->fbdefio = NULL;
+ }
+ }
}
pr_debug("open /dev/fb%d user=%d fb_info=%p count=%d",
--
2.55.0