Re: [PATCH] iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX
Benjamin Block <[email protected]>
| Newsgroups | org.kernel.vger.linux-s390,dev.linux.lists.iommu,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Aug 18, 2026 at 09:13:17PM +0200, Niklas Schnelle wrote: > When using a 5-level translation table via ZPCI_TABLE_TYPE_RFX > get_rso_from_iova() returns NULL when the region-first entry is invalid. > Yet in get_rto_from_iova() the region-second origin rso is not checked > to be non-NULL before accessing rso[rsx] leading to a NULL pointer > dereference instead of a NULL return when iova_to_phys() is called on > a unmapped IOVA. Fix this by adding the missing NULL check. > > Cc: [email protected] > Fixes: 81244074b518 ("iommu/s390: allow larger region tables") > Signed-off-by: Niklas Schnelle <[email protected]> > --- > drivers/iommu/s390-iommu.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/iommu/s390-iommu.c b/drivers/iommu/s390-iommu.c > index f148f559ac56..58ca7727b7f2 100644 > --- a/drivers/iommu/s390-iommu.c > +++ b/drivers/iommu/s390-iommu.c > @@ -974,6 +974,8 @@ static unsigned long *get_rto_from_iova(struct s390_domain *domain, > case ZPCI_TABLE_TYPE_RFX: > case ZPCI_TABLE_TYPE_RSX: > rso = get_rso_from_iova(domain, iova); > + if (!rso) > + return NULL; > rsx = calc_rsx(iova); > rse = READ_ONCE(rso[rsx]); > if (!reg_entry_isvalid(rse)) Looks good to me! Reviewed-by: Benjamin Block <[email protected]> -- Best Regards, Benjamin Block / Linux on IBM Z Kernel Development IBM Deutschland Research & Development GmbH / https://www.ibm.com/privacy Vors. Aufs.-R.: Wolfgang Wendt / Geschäftsführung: David Faller Sitz der Ges.: Ehningen / Registergericht: AmtsG Stuttgart, HRB 243294