[PATCH v2] iio: adc: ade9000: fix NULL pointer dereference in clkout registration

Linmao Li posted 1 patch 1 month ago
drivers/iio/adc/ade9000.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
[PATCH v2] iio: adc: ade9000: fix NULL pointer dereference in clkout registration
Posted by Linmao Li 1 month ago
ade9000_setup_clkout() passes NULL as the register address when
registering a divider clock. During clock registration, the common
clock framework calls clk_divider_recalc_rate(), which dereferences
the address through readl(). As a result, probing an ADE9000 configured
as a clock provider with an external input clock crashes.

CLKOUT passes CLKIN through without changing its rate. Register it as
a 1:1 fixed-factor clock, which does not require register access.

This change does not affect the configuration using the internal clock,
for which the driver does not register a clock provider.

Fixes: 81de7b4619fc ("iio: adc: add ade9000 support")
Cc: stable@vger.kernel.org
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
---
Changes in v2:
- Clarify that the configuration using the internal clock is unaffected.

 drivers/iio/adc/ade9000.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/iio/adc/ade9000.c b/drivers/iio/adc/ade9000.c
index e57e24b6acdf7..4e96cc37fbedf 100644
--- a/drivers/iio/adc/ade9000.c
+++ b/drivers/iio/adc/ade9000.c
@@ -1647,8 +1647,9 @@ static int ade9000_setup_clkout(struct device *dev, struct ade9000_state *st)
 		return 0;
 
 	/* CLKOUT passes through CLKIN with divider of 1 */
-	clkout_hw = devm_clk_hw_register_divider(dev, "clkout", __clk_get_name(st->clkin),
-						 CLK_SET_RATE_PARENT, NULL, 0, 1, 0, NULL);
+	clkout_hw = devm_clk_hw_register_fixed_factor(dev, "clkout",
+						      __clk_get_name(st->clkin),
+						      CLK_SET_RATE_PARENT, 1, 1);
 	if (IS_ERR(clkout_hw))
 		return dev_err_probe(dev, PTR_ERR(clkout_hw), "Failed to register clkout");
 

base-commit: 6b9f23b5460818aaf199dda90210d5fc08d66c8f
-- 
2.25.1
Re: [PATCH v2] iio: adc: ade9000: fix NULL pointer dereference in clkout registration
Posted by Jonathan Cameron 4 weeks ago
On Wed, 26 Aug 2026 16:31:56 +0800
Linmao Li <lilinmao@kylinos.cn> wrote:

> ade9000_setup_clkout() passes NULL as the register address when
> registering a divider clock. During clock registration, the common
> clock framework calls clk_divider_recalc_rate(), which dereferences
> the address through readl(). As a result, probing an ADE9000 configured
> as a clock provider with an external input clock crashes.
> 
> CLKOUT passes CLKIN through without changing its rate. Register it as
> a 1:1 fixed-factor clock, which does not require register access.
> 
> This change does not affect the configuration using the internal clock,
> for which the driver does not register a clock provider.
> 
> Fixes: 81de7b4619fc ("iio: adc: add ade9000 support")
> Cc: stable@vger.kernel.org
> Signed-off-by: Linmao Li <lilinmao@kylinos.cn>

Looking for a tag from Antoniu for this one.

> ---
> Changes in v2:
> - Clarify that the configuration using the internal clock is unaffected.
> 
>  drivers/iio/adc/ade9000.c | 5 +++--
>  1 file changed, 3 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/iio/adc/ade9000.c b/drivers/iio/adc/ade9000.c
> index e57e24b6acdf7..4e96cc37fbedf 100644
> --- a/drivers/iio/adc/ade9000.c
> +++ b/drivers/iio/adc/ade9000.c
> @@ -1647,8 +1647,9 @@ static int ade9000_setup_clkout(struct device *dev, struct ade9000_state *st)
>  		return 0;
>  
>  	/* CLKOUT passes through CLKIN with divider of 1 */
> -	clkout_hw = devm_clk_hw_register_divider(dev, "clkout", __clk_get_name(st->clkin),
> -						 CLK_SET_RATE_PARENT, NULL, 0, 1, 0, NULL);
> +	clkout_hw = devm_clk_hw_register_fixed_factor(dev, "clkout",
> +						      __clk_get_name(st->clkin),
> +						      CLK_SET_RATE_PARENT, 1, 1);
>  	if (IS_ERR(clkout_hw))
>  		return dev_err_probe(dev, PTR_ERR(clkout_hw), "Failed to register clkout");
>  
> 
> base-commit: 6b9f23b5460818aaf199dda90210d5fc08d66c8f
Re: [PATCH v2] iio: adc: ade9000: fix NULL pointer dereference in clkout registration
Posted by Jonathan Cameron 1 week ago
On Mon, 31 Aug 2026 00:57:28 +0100
Jonathan Cameron <jic23@kernel.org> wrote:

> On Wed, 26 Aug 2026 16:31:56 +0800
> Linmao Li <lilinmao@kylinos.cn> wrote:
> 
> > ade9000_setup_clkout() passes NULL as the register address when
> > registering a divider clock. During clock registration, the common
> > clock framework calls clk_divider_recalc_rate(), which dereferences
> > the address through readl(). As a result, probing an ADE9000 configured
> > as a clock provider with an external input clock crashes.
> > 
> > CLKOUT passes CLKIN through without changing its rate. Register it as
> > a 1:1 fixed-factor clock, which does not require register access.
> > 
> > This change does not affect the configuration using the internal clock,
> > for which the driver does not register a clock provider.
> > 
> > Fixes: 81de7b4619fc ("iio: adc: add ade9000 support")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: Linmao Li <lilinmao@kylinos.cn>  
> 
> Looking for a tag from Antoniu for this one.
Antoniu

Please take a look at this.

Jonathan

> 
> > ---
> > Changes in v2:
> > - Clarify that the configuration using the internal clock is unaffected.
> > 
> >  drivers/iio/adc/ade9000.c | 5 +++--
> >  1 file changed, 3 insertions(+), 2 deletions(-)
> > 
> > diff --git a/drivers/iio/adc/ade9000.c b/drivers/iio/adc/ade9000.c
> > index e57e24b6acdf7..4e96cc37fbedf 100644
> > --- a/drivers/iio/adc/ade9000.c
> > +++ b/drivers/iio/adc/ade9000.c
> > @@ -1647,8 +1647,9 @@ static int ade9000_setup_clkout(struct device *dev, struct ade9000_state *st)
> >  		return 0;
> >  
> >  	/* CLKOUT passes through CLKIN with divider of 1 */
> > -	clkout_hw = devm_clk_hw_register_divider(dev, "clkout", __clk_get_name(st->clkin),
> > -						 CLK_SET_RATE_PARENT, NULL, 0, 1, 0, NULL);
> > +	clkout_hw = devm_clk_hw_register_fixed_factor(dev, "clkout",
> > +						      __clk_get_name(st->clkin),
> > +						      CLK_SET_RATE_PARENT, 1, 1);
> >  	if (IS_ERR(clkout_hw))
> >  		return dev_err_probe(dev, PTR_ERR(clkout_hw), "Failed to register clkout");
> >  
> > 
> > base-commit: 6b9f23b5460818aaf199dda90210d5fc08d66c8f  
> 
>