[PATCH 2/5] tpm: tpm_nsc: fix NULL pointer dereference on init failure
From: Pei Xiao
Date: Sat Oct 03 2026 - 04:28:52 EST
tpm_nsc_remove() is used as the release callback of the hand-created
platform device and dereferences the chip drvdata unconditionally.
If init fails before tpmm_chip_alloc() (e.g. request_region() cannot
claim the ports), the error path drops the last device reference and
the release callback runs with chip == NULL, crashing module init.
Return early when the chip has not been created yet.
Fixes: afb5abc262e9 ("tpm: two-phase chip management functions")
Assisted-by: GLM-5.3
Signed-off-by: Pei Xiao <xiaopei01@xxxxxxxxxx>
---
drivers/char/tpm/tpm_nsc.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/char/tpm/tpm_nsc.c b/drivers/char/tpm/tpm_nsc.c
index 879ac88f5783..46a52dc99b14 100644
--- a/drivers/char/tpm/tpm_nsc.c
+++ b/drivers/char/tpm/tpm_nsc.c
@@ -259,7 +259,12 @@ static struct platform_device *pdev = NULL;
static void tpm_nsc_remove(struct device *dev)
{
struct tpm_chip *chip = dev_get_drvdata(dev);
- struct tpm_nsc_priv *priv = dev_get_drvdata(&chip->dev);
+ struct tpm_nsc_priv *priv;
+
+ if (!chip)
+ return;
+
+ priv = dev_get_drvdata(&chip->dev);
tpm_chip_unregister(chip);
release_region(priv->base, 2);
--
2.25.1