[PATCH] leds: is31fl32xx: Fix NULL pointer dereference when binding via I2C ID table
From: Rosen Penev
Date: Mon Oct 05 2026 - 15:49:36 EST
If the device binds via the I2C ID table (e.g., fallback matching by
node name, sysfs new_device, or software node),
device_get_match_data() in is31fl32xx_probe() returns NULL because
the is31fl32xx_id table entries have no .driver_data.
Without a NULL check, is31fl32xx_parse_dt() will unconditionally
dereference cdef when checking cdef->output_frequency_setting_reg,
and is31fl32xx_parse_child_dt() will dereference cdef->channels,
leading to a NULL pointer dereference and kernel oops.
Add a NULL check for cdef alongside the existing child count check in
is31fl32xx_probe(), returning -EINVAL if no match data is available.
Fixes: 2779f4724b2f ("leds: various: use device_get_match_data")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
---
drivers/leds/leds-is31fl32xx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/leds/leds-is31fl32xx.c b/drivers/leds/leds-is31fl32xx.c
index 285085d27453..7bb0295b0b49 100644
--- a/drivers/leds/leds-is31fl32xx.c
+++ b/drivers/leds/leds-is31fl32xx.c
@@ -577,7 +577,7 @@ static int is31fl32xx_probe(struct i2c_client *client)
cdef = device_get_match_data(dev);
count = device_get_child_node_count(dev);
- if (!count)
+ if (!cdef || !count)
return -EINVAL;
priv = devm_kzalloc(dev, struct_size(priv, leds, count),
--
2.56.0