[PATCH v3] of/address: Fix NULL bus dereference in of_pci_range_parser_one()

From: Carlo Caione

Date: Mon Jul 27 2026 - 04:37:31 EST


The bus matching rework made of_match_bus() return NULL for nodes with
ranges/dma-ranges but no local #address-cells. parser_init() stored that
NULL bus, and the range iterator later dereferenced it.

Reject such nodes in parser_init(), leaving an explicit empty
iterator for callers that ignore the init return, and make
of_dma_get_max_cpu_address() honour the init failure so a rejected node
cannot clamp the DMA limit.

Fixes: 64ee3cf096ac ("of/address: Rework bus matching to avoid warnings")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Carlo Caione <ccaione@xxxxxxxxxxxx>
---
Changes in v3:
- Drop the of_range_count() hunk in of_dma_get_max_cpu_address(): it
guarded a pre-existing corner, not this regression (Rob)
- Link to v2: https://lore.kernel.org/r/20260706114731.57353-1-ccaione@xxxxxxxxxxxx

Changes in v2:
- Validate na/pna/ns in parser_init() with OF_CHECK_COUNTS() /
OF_CHECK_ADDR_COUNT()
- Link to v1: https://lore.kernel.org/r/20260706095651.48839-1-ccaione@xxxxxxxxxxxx
---
drivers/of/address.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)

diff --git a/drivers/of/address.c b/drivers/of/address.c
index cf4aab11e9b1..499d37ceae21 100644
--- a/drivers/of/address.c
+++ b/drivers/of/address.c
@@ -753,6 +753,7 @@ EXPORT_SYMBOL(of_property_read_reg);
static int parser_init(struct of_pci_range_parser *parser,
struct device_node *node, const char *name)
{
+ const __be32 *range;
int rlen;

parser->node = node;
@@ -761,12 +762,20 @@ static int parser_init(struct of_pci_range_parser *parser,
parser->ns = of_bus_n_size_cells(node);
parser->dma = !strcmp(name, "dma-ranges");
parser->bus = of_match_bus(node);
+ parser->range = NULL;
+ parser->end = NULL;

- parser->range = of_get_property(node, name, &rlen);
- if (parser->range == NULL)
+ range = of_get_property(node, name, &rlen);
+ if (!range)
return -ENOENT;

- parser->end = parser->range + rlen / sizeof(__be32);
+ if (!parser->bus ||
+ !OF_CHECK_COUNTS(parser->na, parser->ns) ||
+ !OF_CHECK_ADDR_COUNT(parser->pna))
+ return -EINVAL;
+
+ parser->range = range;
+ parser->end = range + rlen / sizeof(__be32);

return 0;
}
@@ -792,7 +801,7 @@ struct of_pci_range *of_pci_range_parser_one(struct of_pci_range_parser *parser,
int na = parser->na;
int ns = parser->ns;
int np = parser->pna + na + ns;
- int busflag_na = parser->bus->flag_cells;
+ int busflag_na;

if (!range)
return NULL;
@@ -800,6 +809,8 @@ struct of_pci_range *of_pci_range_parser_one(struct of_pci_range_parser *parser,
if (!parser->range || parser->range + np > parser->end)
return NULL;

+ busflag_na = parser->bus->flag_cells;
+
range->flags = parser->bus->get_flags(parser->range);

range->bus_addr = of_read_number(parser->range + busflag_na, na - busflag_na);
@@ -976,8 +987,7 @@ phys_addr_t __init of_dma_get_max_cpu_address(struct device_node *np)
np = of_root;

ranges = of_get_property(np, "dma-ranges", &len);
- if (ranges && len) {
- of_dma_range_parser_init(&parser, np);
+ if (ranges && len && !of_dma_range_parser_init(&parser, np)) {
for_each_of_range(&parser, &range)
if (range.cpu_addr + range.size > cpu_end)
cpu_end = range.cpu_addr + range.size - 1;

---
base-commit: 8cdeaa50eae8dad34885515f62559ee83e7e8dda
change-id: 20260727-of-range-parser-null-bus-9f87bbf440ee

Best regards,
--
Carlo Caione <ccaione@xxxxxxxxxxxx>