Re: [PATCH] PCI: imx6: Avoid dereferencing a NULL clock name

[email protected] Sun, 02 Aug 2026 11:14:43 +0000
Newsgroups org.kernel.vger.linux-pci,dev.linux.lists.imx
Message-ID <[email protected]>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The patch successfully fixes a NULL pointer dereference in `imx_pcie_probe()` by checking `imx_pcie->clks[i].id` before passing it to `strncmp()`, but it misses an identical preexisting vulnerability in `imx_setup_phy_mpll()`.
--

--- Patch [1]: [PATCH] PCI: imx6: Avoid dereferencing a NULL clock name ---
commit 59f2384c27b018977b395ad505a6ac37e2ecf39a
Author: Rudi Heitbaum <[email protected]>

PCI: imx6: Avoid dereferencing a NULL clock name
    
This patch fixes a kernel oops in imx_pcie_probe() by checking if
clk_bulk_data::id is NULL before passing it to strncmp(). This happens
because of_clk_bulk_get() legally leaves the id as NULL for unnamed clocks.

> diff --git a/drivers/pci/controller/dwc/pci-imx6.c b/drivers/pci/controller/dwc/pci-imx6.c
> index 98e1db751132a..9a9efc2ab894a 100644
> --- a/drivers/pci/controller/dwc/pci-imx6.c
> +++ b/drivers/pci/controller/dwc/pci-imx6.c
> @@ -1826,7 +1826,8 @@ static int imx_pcie_probe(struct platform_device *pdev)
>  		return dev_err_probe(dev, imx_pcie->num_clks,
>  				     "failed to get clocks\n");
>  	for (i = 0; i < imx_pcie->num_clks; i++)
> -		if (strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
> +		if (imx_pcie->clks[i].id &&
> +		    strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
>  			imx_pcie->enable_ext_refclk = true;
>  
>  	if (imx_check_flag(imx_pcie, IMX_PCIE_FLAG_HAS_PHYDRV)) {

[Severity: High]
This is a pre-existing issue, but this same vulnerability appears to exist
elsewhere in this driver.

In imx_setup_phy_mpll(), the driver iterates over the clocks and calls
strncmp() on the id without checking if it is NULL:

drivers/pci/controller/dwc/pci-imx6.c:imx_setup_phy_mpll() {
    ...
	for (i = 0; i < imx_pcie->num_clks; i++)
		if (strncmp(clks[i].id, "pcie_phy", 8) == 0)
			phy_rate = clk_get_rate(clks[i].clk);
    ...
}

Could this cause a similar oops during probe when IMX_PCIE_FLAG_IMX_PHY is
used and an unnamed clock is present? Would it make sense to apply the same
NULL check to this loop?

-- 
Sashiko AI review ยท https://sashiko.dev/#/patchset/am8iBwJSEhYhWTqk@6cfee64030a6?part=1