Re: [PATCH] pwm: lp3943: fix NULL pointer dereference for an unconfigured channel

From: Uwe Kleine-König

Date: Tue Sep 08 2026 - 13:25:20 EST


On Sun, Sep 06, 2026 at 05:11:58PM +0530, Manush Prajwal wrote:
> lp3943_pwm_probe() unconditionally registers a pwmchip with
> LP3943_NUM_PWMS(2) hwpwm channels, but lp3943_pwm_parse_dt() only
> populates pdata->pwms[i] for the channels whose ti,pwm0/ti,pwm1
> property is actually present in the devicetree (the binding
> explicitly allows each PWM generator to drive zero or more outputs,
> and lp3943_pwm_parse_dt() only fails outright with -ENODATA if
> *neither* property is present). A devicetree that configures only one
> of the two channels leaves pdata->pwms[] NULL for the other.
>
> lp3943_pwm_request_map() dereferences pdata->pwms[hwpwm] with no NULL
> check:
>
> pwm_map->output = pdata->pwms[hwpwm]->output;
> pwm_map->num_outputs = pdata->pwms[hwpwm]->num_outputs;
>
> so requesting the unconfigured channel (e.g. exporting it from
> sysfs) crashes with a NULL pointer dereference instead of failing
> cleanly.
>
> Return -ENODEV from lp3943_pwm_request_map() when the channel was
> never configured, before the pointer is dereferenced. The caller,
> lp3943_pwm_request(), already propagates an ERR_PTR return correctly
> (it does so today for the existing -EBUSY case).
>
> Reported-by: Sashiko AI review <sashiko-bot@xxxxxxxxxx>
> Closes: https://sashiko.dev/#/patchset/6a9d4c6b.79b5ea6e.147aa1.5883@xxxxxxxxxxxxx?part=1
> Signed-off-by: Manush Prajwal <manushprajwal555@xxxxxxxxx>

Applied to
https://git.kernel.org/pub/scm/linux/kernel/git/ukleinek/linux.git pwm/for-next

adding a Fixes trailer for af66b3c0934e ("pwm: Add LP3943 PWM driver").

I havn't made up my mind yet if I send a fixes PR before 7.3. If I do I
will likely include this patch.

Best regards
Uwe

Attachment: signature.asc
Description: PGP signature