Forwarded: [PATCH] PCI: Handle dev_set_name() failure in pci_setup_device()

From: syzbot

Date: Sat Jul 25 2026 - 06:06:55 EST


For archival purposes, forwarding an incoming command email to
linux-kernel@xxxxxxxxxxxxxxx, syzkaller-bugs@xxxxxxxxxxxxxxxx.

***

Subject: [PATCH] PCI: Handle dev_set_name() failure in pci_setup_device()
Author: rihyeon8648@xxxxxxxxx

#syz test

pci_setup_device() calls dev_set_name() but ignores its return value.
dev_set_name() allocates the name with kvasprintf() and can fail, leaving
dev->kobj.name NULL.

Enumeration then continues with an unnamed device. device_add() rejects
it with -EINVAL because dev_name() returns NULL and pci_bus_type has no
->dev_name callback, but pci_device_add() only WARNs about that failure:

pci (null): [8086:2934] type 00 class 0x0c0300 conventional PCI endpoint
pci (null): BAR 4 [io 0xc0e0-0xc0ff]
------------[ cut here ]------------
ret < 0
WARNING: drivers/pci/probe.c:2768 at pci_device_add+0x133b/0x1810
Call Trace:
pci_scan_single_device+0x1d0/0x240
pci_scan_slot+0x1c9/0x7c0
pci_scan_child_bus_extend+0x6b/0x7b0
pci_rescan_bus+0x18/0x40
rescan_store+0xfb/0x130

The device was already put on bus->devices before device_add() ran and is
not removed from it, so pci_bus_add_devices() later in the same
pci_rescan_bus() call picks it up and hands it to __device_attach(), which
dereferences dev->p. device_add() freed dev->p on its error path, so this
is a NULL dereference:

Oops: general protection fault, probably for non-canonical address ...
KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f]
RIP: 0010:__device_attach+0xb0/0x4d0
Call Trace:
device_initial_probe+0xaf/0xd0
pci_bus_add_device+0xc5/0x100
pci_bus_add_devices+0x9a/0x1f0
pci_rescan_bus+0x2a/0x40
rescan_store+0xfb/0x130
Kernel panic - not syncing: Fatal exception

Propagate the error instead. pci_setup_device() already returns int and
both callers, pci_scan_device() and pci_iov_scan_device(), release the
device on failure, so no caller changes are needed. Release the OF node
first, matching the existing error path for an unknown header type.

Reported-by: syzbot+87bb32e345aa80c0554b@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=87bb32e345aa80c0554b
Fixes: eebfcfb52ce7 ("PCI: handle pci_name() being const")
Signed-off-by: Rihyeon Kim <rihyeon8648@xxxxxxxxx>
---
drivers/pci/probe.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c
index dd0abbc63e18..474c6cb327be 100644
--- a/drivers/pci/probe.c
+++ b/drivers/pci/probe.c
@@ -2052,9 +2052,13 @@ int pci_setup_device(struct pci_dev *dev)
*/
dev->msi_addr_mask = DMA_BIT_MASK(64);

- dev_set_name(&dev->dev, "%04x:%02x:%02x.%d", pci_domain_nr(dev->bus),
- dev->bus->number, PCI_SLOT(dev->devfn),
- PCI_FUNC(dev->devfn));
+ err = dev_set_name(&dev->dev, "%04x:%02x:%02x.%d",
+ pci_domain_nr(dev->bus), dev->bus->number,
+ PCI_SLOT(dev->devfn), PCI_FUNC(dev->devfn));
+ if (err) {
+ pci_release_of_node(dev);
+ return err;
+ }

class = pci_class(dev);

--
2.43.0