[PATCH] staging: greybus: bootrom: fix potential NULL dereference

From: hanzhijian

Date: Fri Aug 21 2026 - 07:36:01 EST


In gb_bootrom_get_firmware(), the queue_work label dereferences fw->size
on a path where fw may have been set to NULL via the "if (!fw) goto
unlock" path. This is currently masked at runtime by the !ret
short-circuit (ret is non-zero on every path where fw can be NULL), but
it relies on an implicit invariant that is fragile and hard to follow.

Move the next_request calculation into the mutex-protected region where
fw is known to be non-NULL, and initialize next_request to
NEXT_REQ_GET_FIRMWARE so the queue_work label no longer dereferences fw.

Signed-off-by: hanzhijian <hanzhijian1991@xxxxxxxxx>
---
drivers/staging/greybus/bootrom.c | 10 ++++------
1 file changed, 4 insertions(+), 6 deletions(-)

diff --git a/drivers/staging/greybus/bootrom.c b/drivers/staging/greybus/bootrom.c
index 83921d90c..289c9e957 100644
--- a/drivers/staging/greybus/bootrom.c
+++ b/drivers/staging/greybus/bootrom.c
@@ -245,7 +245,7 @@ static int gb_bootrom_get_firmware(struct gb_operation *op)
struct gb_bootrom_get_firmware_request *firmware_request;
struct device *dev = &op->connection->bundle->dev;
unsigned int offset, size;
- enum next_request_type next_request;
+ enum next_request_type next_request = NEXT_REQ_GET_FIRMWARE;
u8 *firmware_response;
int ret = 0;

@@ -293,16 +293,14 @@ static int gb_bootrom_get_firmware(struct gb_operation *op)
dev_dbg(dev, "responding with firmware (offs = %u, size = %u)\n",
offset, size);

+ if (offset + size == fw->size)
+ next_request = NEXT_REQ_READY_TO_BOOT;
+
unlock:
mutex_unlock(&bootrom->mutex);

queue_work:
/* Refresh timeout */
- if (!ret && (offset + size == fw->size))
- next_request = NEXT_REQ_READY_TO_BOOT;
- else
- next_request = NEXT_REQ_GET_FIRMWARE;
-
gb_bootrom_set_timeout(bootrom, next_request, NEXT_REQ_TIMEOUT_MS);

return ret;
--
2.43.0