[lvc-project] [PATCH 1/2] mfd: tps65217: Fix NULL pointer dereference on IRQ init failure

Andreas Kemnade andreas at kemnade.info
Fri Aug 21 12:55:05 MSK 2026


On Fri, 21 Aug 2026 07:53:58 +0000
Жамбакиев Радий Рикардинович <r.zhambakiev at prosoftsystems.ru> wrote:

> tps65217_probe() ignores the return value of tps65217_irq_init(), so
> when the irq domain creation fails the probe still completes and the
> driver ends up bound with a NULL tps->irq_domain. Unloading the
> module then makes tps65217_remove() call irq_domain_remove() on the
> NULL pointer and oops the kernel. On top of that, irq_find_mapping()
> may fall back to the default irq domain and dispose of mappings that
> belong to other interrupt controllers.
> 
> Check the return value and abort the probe on failure so the error
> is reported and no inconsistent state is left for removal.
> 
> Fixes: 6556bdacf646fcaa ("mfd: tps65217: Add support for IRQs")
> Cc: stable at vger.kernel.org
> Signed-off-by: Radiy Zhambakiev <r.zhambakiev at prosoftsystems.ru>

Reviewed-by: Andreas Kemnade <andreas at kemnade.info>

> ---
>  drivers/mfd/tps65217.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/mfd/tps65217.c b/drivers/mfd/tps65217.c
> index c240fac0ede7..2d04d9e0ae29 100644
> --- a/drivers/mfd/tps65217.c
> +++ b/drivers/mfd/tps65217.c
> @@ -333,7 +333,9 @@ static int tps65217_probe(struct i2c_client *client)
>  	}
>  
>  	if (client->irq) {
> -		tps65217_irq_init(tps, client->irq);
> +		ret = tps65217_irq_init(tps, client->irq);
> +		if (ret)
> +			return ret;
>  	} else {
>  		int i;
>  




More information about the lvc-project mailing list