Re: [PATCH 2/5] tpm: tpm_nsc: fix NULL pointer dereference on init failure
From: Jarkko Sakkinen
Date: Mon Oct 05 2026 - 00:18:41 EST
On Sat, Oct 03, 2026 at 04:27:52PM +0800, Pei Xiao wrote:
> tpm_nsc_remove() is used as the release callback of the hand-created
> platform device and dereferences the chip drvdata unconditionally.
> If init fails before tpmm_chip_alloc() (e.g. request_region() cannot
> claim the ports), the error path drops the last device reference and
> the release callback runs with chip == NULL, crashing module init.
>
> Return early when the chip has not been created yet.
>
> Fixes: afb5abc262e9 ("tpm: two-phase chip management functions")
> Assisted-by: GLM-5.3
> Signed-off-by: Pei Xiao <xiaopei01@xxxxxxxxxx>
> ---
> drivers/char/tpm/tpm_nsc.c | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/char/tpm/tpm_nsc.c b/drivers/char/tpm/tpm_nsc.c
> index 879ac88f5783..46a52dc99b14 100644
> --- a/drivers/char/tpm/tpm_nsc.c
> +++ b/drivers/char/tpm/tpm_nsc.c
> @@ -259,7 +259,12 @@ static struct platform_device *pdev = NULL;
> static void tpm_nsc_remove(struct device *dev)
> {
> struct tpm_chip *chip = dev_get_drvdata(dev);
> - struct tpm_nsc_priv *priv = dev_get_drvdata(&chip->dev);
> + struct tpm_nsc_priv *priv;
> +
> + if (!chip)
> + return;
> +
> + priv = dev_get_drvdata(&chip->dev);
>
> tpm_chip_unregister(chip);
> release_region(priv->base, 2);
> --
> 2.25.1
>
I can apply this, thanks.
Reviewed-by: Jarkko Sakkinen <jarkko@xxxxxxxxxx>
Br, Jarkko