Re: [PATCH v2 1/7] s390/pci: Fix double-free and NULL deref in zpci MSI domain cleanup
From: Niklas Schnelle
Date: Tue Oct 06 2026 - 05:47:05 EST
On Mon, 2026-10-05 at 14:03 +0200, Tobias Schumacher wrote:
> zpci_remove_parent_msi_domain() dereferences zbus->msi_parent_domain
> unconditionally and does not clear it afterwards.
>
> zpci_bus_create_pci_bus() removes the domain when pci_create_root_bus()
> fails, then zpci_bus_release() removes it again on the last kref_put(),
> reading ->fwnode from the freed irq_domain and freeing it twice.
>
> If zpci_alloc_domain() or zpci_create_parent_msi_domain() fails, no domain
> is created at all; zbus is kzalloc'd, so the same release path dereferences
> NULL.
>
> Return early when there is no domain, and clear the pointer after removing
> one.
>
> Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Tobias Schumacher <ts@xxxxxxxxxxxxx>
> ---
> arch/s390/pci/pci_irq.c | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c
> index 9c9ed3d8d959..c9520a16ca75 100644
> --- a/arch/s390/pci/pci_irq.c
> +++ b/arch/s390/pci/pci_irq.c
> @@ -533,9 +533,13 @@ void zpci_remove_parent_msi_domain(struct zpci_bus *zbus)
> {
> struct fwnode_handle *fn;
>
> + if (!zbus->msi_parent_domain)
> + return;
> +
> fn = zbus->msi_parent_domain->fwnode;
> irq_domain_remove(zbus->msi_parent_domain);
> irq_domain_free_fwnode(fn);
> + zbus->msi_parent_domain = NULL;
> }
>
> static void __init cpu_enable_directed_irq(void *unused)
Thanks for the fix!
Reviewed-by: Niklas Schnelle <schnelle@xxxxxxxxxxxxx>