[PATCH] usb: typec: ucsi: Fix NULL pointer dereference in power level debugfs

From: Bertrand Jacquin

Date: Sat Oct 10 2026 - 07:04:56 EST


ucsi_register() creates the debugfs entries right away, but
ucsi->connector is only set by ucsi_init(), which runs later from
ucsi->work and only publishes the connectors once the PPM has been
reset and all ports are registered. Until then, or for good if init
fails, ucsi->connector is NULL, yet the peak_current, avg_current and
vbus_voltage show callbacks dereference it unconditionally.

On an Intel NUC13ANKi5 whose PPM never answers when CONFIG_ACPI_EC=n,
reading those files after the failed init oopses:

ucsi_acpi USBC000:00: error -ETIMEDOUT: PPM init failed
BUG: kernel NULL pointer dereference, address: 000000000000045c
#PF: supervisor read access in kernel mode
RIP: 0010:ucsi_debugfs_register+0x291/0x420 [typec_ucsi]
Call Trace:
<TASK>
seq_read_iter+0x1e4/0x4c0
seq_read+0x12b/0x160
full_proxy_read+0x9a/0x1f0
vfs_read+0xba/0x320
ksys_read+0x74/0x110
do_syscall_64+0x79/0x240
entry_SYSCALL_64_after_hwframe+0x71/0x79

Return -ENODEV from those callbacks while no connector is available.

Fixes: c851b71fd6cd ("usb: typec: ucsi: Add support for READ_POWER_LEVEL command")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Bertrand Jacquin <bertrand@xxxxxxxxxxx>
---
drivers/usb/typec/ucsi/debugfs.c | 9 +++++++++
1 file changed, 9 insertions(+)

diff --git a/drivers/usb/typec/ucsi/debugfs.c b/drivers/usb/typec/ucsi/debugfs.c
index 77a0dd75edd3..911a151ac16a 100644
--- a/drivers/usb/typec/ucsi/debugfs.c
+++ b/drivers/usb/typec/ucsi/debugfs.c
@@ -92,6 +92,9 @@ static int ucsi_peak_curr_show(struct seq_file *m, void *v)
{
struct ucsi *ucsi = m->private;

+ if (!ucsi->connector)
+ return -ENODEV;
+
seq_printf(m, "%u mA\n", ucsi->connector->peak_current);
return 0;
}
@@ -101,6 +104,9 @@ static int ucsi_avg_curr_show(struct seq_file *m, void *v)
{
struct ucsi *ucsi = m->private;

+ if (!ucsi->connector)
+ return -ENODEV;
+
seq_printf(m, "%u mA\n", ucsi->connector->avg_current);
return 0;
}
@@ -110,6 +116,9 @@ static int ucsi_vbus_volt_show(struct seq_file *m, void *v)
{
struct ucsi *ucsi = m->private;

+ if (!ucsi->connector)
+ return -ENODEV;
+
seq_printf(m, "%u mV\n", ucsi->connector->vbus_voltage);
return 0;
}