On Fri Mar 20 15:04:53 2026 +0800, Wang Jun wrote:
> Add a check for the return value of pci_ioremap_bar()
> in cx23885_dev_setup().
> If ioremap for BAR0 fails, release the already allocated
> PCI memory region,
> decrement the device count, and return -ENODEV.
> 
> This prevents a potential null pointer dereference and
> ensures proper cleanup
> on memory mapping failure.
> 
> Fixes: d19770e5178a ("V4L/DVB (6150): Add CX23885/CX23887 PCIe bridge driver")
> Cc: [email protected]
> Signed-off-by: Wang Jun <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/pci/cx23885/cx23885-core.c | 14 ++++++++++++--
 1 file changed, 12 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/pci/cx23885/cx23885-core.c 
b/drivers/media/pci/cx23885/cx23885-core.c
index 4a8af8b88d84..9b92e8db494c 100644
--- a/drivers/media/pci/cx23885/cx23885-core.c
+++ b/drivers/media/pci/cx23885/cx23885-core.c
@@ -1002,8 +1002,12 @@ static int cx23885_dev_setup(struct cx23885_dev *dev)
        }
 
        /* PCIe stuff */
-       dev->lmmio = ioremap(pci_resource_start(dev->pci, 0),
-                            pci_resource_len(dev->pci, 0));
+       dev->lmmio = pci_ioremap_bar(dev->pci, 0);
+       if (!dev->lmmio) {
+               dev_err(&dev->pci->dev, "CORE %s: can't ioremap MMIO memory\n",
+                       dev->name);
+               goto err_release_region;
+       }
 
        dev->bmmio = (u8 __iomem *)dev->lmmio;
 
@@ -1109,6 +1113,12 @@ static int cx23885_dev_setup(struct cx23885_dev *dev)
        }
 
        return 0;
+
+err_release_region:
+       release_mem_region(pci_resource_start(dev->pci, 0),
+                          pci_resource_len(dev->pci, 0));
+       cx23885_devcount--;
+       return -ENODEV;
 }
 
 static void cx23885_dev_unregister(struct cx23885_dev *dev)
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to