[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <SJ0PR03MB625357900B5B71F5A770874E8E7F9@SJ0PR03MB6253.namprd03.prod.outlook.com>
Date: Mon, 5 Sep 2022 11:46:59 +0000
From: "Hennerich, Michael" <Michael.Hennerich@...log.com>
To: Wei Yongjun <weiyongjun1@...wei.com>,
Sebastian Reichel <sre@...nel.org>
CC: "linux-pm@...r.kernel.org" <linux-pm@...r.kernel.org>,
"linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>
Subject: RE: [PATCH -next 1/2] power: supply: adp5061: fix out-of-bounds read
in adp5061_get_chg_type()
> -----Original Message-----
> From: Wei Yongjun <weiyongjun1@...wei.com>
> Sent: Samstag, 27. August 2022 09:32
> To: Hennerich, Michael <Michael.Hennerich@...log.com>; Sebastian
> Reichel <sre@...nel.org>
> Cc: Wei Yongjun <weiyongjun1@...wei.com>; linux-pm@...r.kernel.org;
> linux-kernel@...r.kernel.org
> Subject: [PATCH -next 1/2] power: supply: adp5061: fix out-of-bounds read in
> adp5061_get_chg_type()
>
>
> ADP5061_CHG_STATUS_1_CHG_STATUS is masked with 0x07, which means
> a length of 8, but adp5061_chg_type array size is 4, may end up reading 4
> elements beyond the end of the adp5061_chg_type[] array.
>
> Signed-off-by: Wei Yongjun <weiyongjun1@...wei.com>
Acked-by: Michael Hennerich <michael.hennerich@...log.com>
> ---
> drivers/power/supply/adp5061.c | 6 +++---
> 1 file changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/power/supply/adp5061.c
> b/drivers/power/supply/adp5061.c index 003557043ab3..daee1161c305
> 100644
> --- a/drivers/power/supply/adp5061.c
> +++ b/drivers/power/supply/adp5061.c
> @@ -427,11 +427,11 @@ static int adp5061_get_chg_type(struct
> adp5061_state *st,
> if (ret < 0)
> return ret;
>
> - chg_type =
> adp5061_chg_type[ADP5061_CHG_STATUS_1_CHG_STATUS(status1)];
> - if (chg_type > ADP5061_CHG_FAST_CV)
> + chg_type = ADP5061_CHG_STATUS_1_CHG_STATUS(status1);
> + if (chg_type >= ARRAY_SIZE(adp5061_chg_type))
> val->intval = POWER_SUPPLY_STATUS_UNKNOWN;
> else
> - val->intval = chg_type;
> + val->intval = adp5061_chg_type[chg_type];
>
> return ret;
> }
> --
> 2.34.1
Powered by blists - more mailing lists