diff mbox series

[-next,1/2] power: supply: adp5061: fix out-of-bounds read in adp5061_get_chg_type()

Message ID 20220827073224.713803-2-weiyongjun1@huawei.com
State Accepted
Commit 9d47e01b9d807808224347935562f7043a358054
Headers show
Series [-next,1/2] power: supply: adp5061: fix out-of-bounds read in adp5061_get_chg_type() | expand

Commit Message

Wei Yongjun Aug. 27, 2022, 7:32 a.m. UTC
ADP5061_CHG_STATUS_1_CHG_STATUS is masked with 0x07, which means a length
of 8, but adp5061_chg_type array size is 4, may end up reading 4 elements
beyond the end of the adp5061_chg_type[] array.

Signed-off-by: Wei Yongjun <weiyongjun1@huawei.com>
---
 drivers/power/supply/adp5061.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

Comments

Hennerich, Michael Sept. 5, 2022, 11:46 a.m. UTC | #1
> -----Original Message-----
> From: Wei Yongjun <weiyongjun1@huawei.com>
> Sent: Samstag, 27. August 2022 09:32
> To: Hennerich, Michael <Michael.Hennerich@analog.com>; Sebastian
> Reichel <sre@kernel.org>
> Cc: Wei Yongjun <weiyongjun1@huawei.com>; linux-pm@vger.kernel.org;
> linux-kernel@vger.kernel.org
> Subject: [PATCH -next 1/2] power: supply: adp5061: fix out-of-bounds read in
> adp5061_get_chg_type()
> 
> 
> ADP5061_CHG_STATUS_1_CHG_STATUS is masked with 0x07, which means
> a length of 8, but adp5061_chg_type array size is 4, may end up reading 4
> elements beyond the end of the adp5061_chg_type[] array.
> 
> Signed-off-by: Wei Yongjun <weiyongjun1@huawei.com>

Acked-by: Michael Hennerich <michael.hennerich@analog.com>

> ---
>  drivers/power/supply/adp5061.c | 6 +++---
>  1 file changed, 3 insertions(+), 3 deletions(-)
> 
> diff --git a/drivers/power/supply/adp5061.c
> b/drivers/power/supply/adp5061.c index 003557043ab3..daee1161c305
> 100644
> --- a/drivers/power/supply/adp5061.c
> +++ b/drivers/power/supply/adp5061.c
> @@ -427,11 +427,11 @@ static int adp5061_get_chg_type(struct
> adp5061_state *st,
>  	if (ret < 0)
>  		return ret;
> 
> -	chg_type =
> adp5061_chg_type[ADP5061_CHG_STATUS_1_CHG_STATUS(status1)];
> -	if (chg_type > ADP5061_CHG_FAST_CV)
> +	chg_type = ADP5061_CHG_STATUS_1_CHG_STATUS(status1);
> +	if (chg_type >= ARRAY_SIZE(adp5061_chg_type))
>  		val->intval = POWER_SUPPLY_STATUS_UNKNOWN;
>  	else
> -		val->intval = chg_type;
> +		val->intval = adp5061_chg_type[chg_type];
> 
>  	return ret;
>  }
> --
> 2.34.1
diff mbox series

Patch

diff --git a/drivers/power/supply/adp5061.c b/drivers/power/supply/adp5061.c
index 003557043ab3..daee1161c305 100644
--- a/drivers/power/supply/adp5061.c
+++ b/drivers/power/supply/adp5061.c
@@ -427,11 +427,11 @@  static int adp5061_get_chg_type(struct adp5061_state *st,
 	if (ret < 0)
 		return ret;
 
-	chg_type = adp5061_chg_type[ADP5061_CHG_STATUS_1_CHG_STATUS(status1)];
-	if (chg_type > ADP5061_CHG_FAST_CV)
+	chg_type = ADP5061_CHG_STATUS_1_CHG_STATUS(status1);
+	if (chg_type >= ARRAY_SIZE(adp5061_chg_type))
 		val->intval = POWER_SUPPLY_STATUS_UNKNOWN;
 	else
-		val->intval = chg_type;
+		val->intval = adp5061_chg_type[chg_type];
 
 	return ret;
 }