[tip: x86/urgent] x86/amd_node: Prevent potential NULL pointer dereference

tip-bot2 for Jason Andryuk posted 1 patch 3 weeks, 2 days ago
arch/x86/kernel/amd_node.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
[tip: x86/urgent] x86/amd_node: Prevent potential NULL pointer dereference
Posted by tip-bot2 for Jason Andryuk 3 weeks, 2 days ago
The following commit has been merged into the x86/urgent branch of tip:

Commit-ID:     60714fb1d494e11d1eb54b0aef45e250c51279a8
Gitweb:        https://git.kernel.org/tip/60714fb1d494e11d1eb54b0aef45e250c51279a8
Author:        Jason Andryuk <jason.andryuk@amd.com>
AuthorDate:    Tue, 25 Aug 2026 17:48:03 -04:00
Committer:     Borislav Petkov (AMD) <bp@alien8.de>
CommitterDate: Wed, 02 Sep 2026 13:52:15 -07:00

x86/amd_node: Prevent potential NULL pointer dereference

amd_smn_read/write() are exported functions around __amd_smn_rw(), so
they are always available even if amd_smn_init() fails. In that case,
amd_roots is NULL and __amd_smn_rw() will access uninitialized memory.

Then, commit

  83518453074d ("x86/amd_node: Add SMN offsets to exclusive region access")

added smn_exclusive which indicated the calls to
pci_request_config_region_exclusive() succeeded to prevent concurrent
userspace access.

Commit

  0a4b61d9c2e4 ("x86/amd_node: Fix AMD root device caching")

re-ordered initialization so pci_request_config_region_exclusive() is called
earlier and a failure exits amd_smn_init() before allocating amd_roots.
Setting smn_exclusive moved to the end of amd_smn_init(), after amd_roots is
allocated. It became redundant and can be removed.

Replace smn_exclusive with directly checking amd_roots to avoid a potential
NULL pointer dereference.

  [ bp: Reorg commit message, touchup comment. ]

Fixes: 77466b798d59 ("x86/amd_node: Remove dependency on AMD_NB")
Signed-off-by: Jason Andryuk <jason.andryuk@amd.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Yazen Ghannam <yazen.ghannam@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260825214805.39148-3-jason.andryuk@amd.com
---
 arch/x86/kernel/amd_node.c | 14 ++++++++------
 1 file changed, 8 insertions(+), 6 deletions(-)

diff --git a/arch/x86/kernel/amd_node.c b/arch/x86/kernel/amd_node.c
index 408b9fd..7625857 100644
--- a/arch/x86/kernel/amd_node.c
+++ b/arch/x86/kernel/amd_node.c
@@ -38,7 +38,6 @@ static struct pci_dev **amd_roots;
 
 /* Protect the PCI config register pairs used for SMN. */
 static DEFINE_MUTEX(smn_mutex);
-static bool smn_exclusive;
 
 #define SMN_INDEX_OFFSET	0x60
 #define SMN_DATA_OFFSET		0x64
@@ -91,11 +90,16 @@ static int __amd_smn_rw(u8 i_off, u8 d_off, u16 node, u32 address, u32 *value, b
 	if (node >= amd_num_nodes())
 		return err;
 
-	root = amd_roots[node];
-	if (!root)
+	/*
+	 * Uninitialized amd_roots indicates pci_request_config_region_exclusive()
+	 * didn't run or failed and thus the kernel cannot rely on having
+	 * exclusive access to SMN registers so prevent that.
+	 */
+	if (!amd_roots)
 		return err;
 
-	if (!smn_exclusive)
+	root = amd_roots[node];
+	if (!root)
 		return err;
 
 	guard(mutex)(&smn_mutex);
@@ -313,8 +317,6 @@ static int __init amd_smn_init(void)
 		debugfs_create_file("value",	0600, debugfs_dir, NULL, &smn_value_fops);
 	}
 
-	smn_exclusive = true;
-
 	return 0;
 }