RE: [PATCH 1/3] platform/x86/intel/pmt: Fix NULL dereference when reading crashlog data
From: Ruhl, Michael J
Date: Fri Oct 02 2026 - 08:46:50 EST
>-----Original Message-----
>From: David E. Box <david.e.box@xxxxxxxxxxxxxxx>
>Sent: Thursday, October 1, 2026 6:04 PM
>To: ilpo.jarvinen@xxxxxxxxxxxxxxx; david.e.box@xxxxxxxxxxxxxxx; linux-
>kernel@xxxxxxxxxxxxxxx; platform-driver-x86@xxxxxxxxxxxxxxx; Vivi, Rodrigo
><rodrigo.vivi@xxxxxxxxx>; Ruhl, Michael J <michael.j.ruhl@xxxxxxxxx>; Siddiqui,
>Ayaz A <ayaz.siddiqui@xxxxxxxxx>; Muqthyar Ahmed, Syed Abdul
><syed.abdul.muqthyar.ahmed@xxxxxxxxx>; intel-xe@xxxxxxxxxxxxxxxxxxxxx;
>hansg@xxxxxxxxxx
>Cc: stable@xxxxxxxxxxxxxxx
>Subject: [PATCH 1/3] platform/x86/intel/pmt: Fix NULL dereference when
>reading crashlog data
>
>Commit 353042d54d82 ("platform/x86/intel/vsec: Switch exported helpers
>from
>pci_dev to device") changed intel_pmt_read() to pass entry->ep->dev to
>pmt_telem_read_mmio() in place of entry->pcidev. entry->ep is only
>allocated by the telemetry namespace's pmt_add_endpoint() hook. Crashlog
>entries never get one, so any read() of a crashlog sysfs data file
>dereferences a NULL pointer.
>
>Use the intel_vsec_device parent device instead. The PMT class device is a
>child of the auxiliary device, so derive it the same way
>intel_pmt_attr_visible() does. This is the same device telemetry stored in
>ep->dev, so behavior for telemetry and any read_telem() callback is
>unchanged.
>
>Fixes: 353042d54d82 ("platform/x86/intel/vsec: Switch exported helpers from
>pci_dev to device")
>Cc: stable@xxxxxxxxxxxxxxx
>Assisted-by: LLM
>Signed-off-by: David E. Box <david.e.box@xxxxxxxxxxxxxxx>
>---
> drivers/platform/x86/intel/pmt/class.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
>diff --git a/drivers/platform/x86/intel/pmt/class.c
>b/drivers/platform/x86/intel/pmt/class.c
>index d0ab8e33c62a..b69c79785d9c 100644
>--- a/drivers/platform/x86/intel/pmt/class.c
>+++ b/drivers/platform/x86/intel/pmt/class.c
>@@ -90,6 +90,8 @@ intel_pmt_read(struct file *filp, struct kobject *kobj,
> struct intel_pmt_entry *entry = container_of(attr,
> struct intel_pmt_entry,
> pmt_bin_attr);
>+ struct device *dev = kobj_to_dev(kobj);
>+ struct intel_vsec_device *ivdev =
>auxdev_to_ivdev(to_auxiliary_dev(dev->parent));
>
> if (off < 0)
> return -EINVAL;
>@@ -100,7 +102,7 @@ intel_pmt_read(struct file *filp, struct kobject *kobj,
> if (count > entry->size - off)
> count = entry->size - off;
>
>- count = pmt_telem_read_mmio(entry->ep->dev, entry->cb, entry-
>>header.guid, buf,
>+ count = pmt_telem_read_mmio(ivdev->dev, entry->cb, entry-
>>header.guid, buf,
> entry->base, off, count);
Hi Ilpo, David,
My patch:
[PATCH v11 01/20] platform/x86/intel/pmt: complete pcidev to device update
Fixes this issue in a slightly different way... (uses entry->dev rather than entry->pcidev).
David,
In my patch I have also updated the intel_pmt_get_features() function to use the
entry->dev value (rather than entry->ep->dev).
I think the ep->dev is for Telemetry access, and "features" is a general usage?
Should the _get_features stay entry->ep->dev? or is entry->dev "more correct"?
Thanks
Mike
> return count;
>--
>2.43.0