Thread (6 messages) flat view 6 messages, 3 authors, 2013-09-18

Re: [PATCH] input: pxa27x_keypad: fix NULL pointer dereference

From: Marek Vasut <marex@denx.de>
Date: 2013-09-16 16:49:55

Dear Mike Dunn,
quoted hunk ↗ jump to hunk
A NULL pointer dereference exception occurs in the driver probe function
when device tree is used.  The pdata pointer will be NULL in this case,
but the code dereferences it in all cases.  When device tree is used, a
platform data structure is allocated and initialized, and in all cases
this pointer is copied to the driver's private data, so the variable being
tested should be accessed through the driver's private data structure.

Signed-off-by: Mike Dunn <redacted>
---
 drivers/input/keyboard/pxa27x_keypad.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/input/keyboard/pxa27x_keypad.c
b/drivers/input/keyboard/pxa27x_keypad.c index 134c3b4..3b2a614 100644
--- a/drivers/input/keyboard/pxa27x_keypad.c
+++ b/drivers/input/keyboard/pxa27x_keypad.c
@@ -795,8 +795,10 @@ static int pxa27x_keypad_probe(struct platform_device
*pdev) goto failed_put_clk;
 	}

-	if ((pdata->enable_rotary0 && keypad->rotary_rel_code[0] != -1) ||
-	    (pdata->enable_rotary1 && keypad->rotary_rel_code[1] != -1)) {
+	if ((keypad->pdata->enable_rotary0 &&
+	     keypad->rotary_rel_code[0] != -1) ||
+	    (keypad->pdata->enable_rotary1 &&
+	     keypad->rotary_rel_code[1] != -1)) {
 		input_dev->evbit[0] |= BIT_MASK(EV_REL);
 	}
Nice find. Acked-by: Marek Vasut [off-list ref]

Best regards,
Marek Vasut
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help