diff options
author | Wei Yongjun <weiyongjun1@huawei.com> | 2022-08-27 10:32:23 +0300 |
---|---|---|
committer | Sebastian Reichel <sre@kernel.org> | 2022-09-11 13:18:59 +0300 |
commit | 9d47e01b9d807808224347935562f7043a358054 (patch) | |
tree | c529c100f9605a713477c4e4662d260326988cb6 /drivers/power | |
parent | 3eb7508d0bad13c2c4272fe30adfb02190294290 (diff) | |
download | linux-9d47e01b9d807808224347935562f7043a358054.tar.xz |
power: supply: adp5061: fix out-of-bounds read in adp5061_get_chg_type()
ADP5061_CHG_STATUS_1_CHG_STATUS is masked with 0x07, which means a length
of 8, but adp5061_chg_type array size is 4, may end up reading 4 elements
beyond the end of the adp5061_chg_type[] array.
Signed-off-by: Wei Yongjun <weiyongjun1@huawei.com>
Acked-by: Michael Hennerich <michael.hennerich@analog.com>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Diffstat (limited to 'drivers/power')
-rw-r--r-- | drivers/power/supply/adp5061.c | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/drivers/power/supply/adp5061.c b/drivers/power/supply/adp5061.c index 003557043ab3..daee1161c305 100644 --- a/drivers/power/supply/adp5061.c +++ b/drivers/power/supply/adp5061.c @@ -427,11 +427,11 @@ static int adp5061_get_chg_type(struct adp5061_state *st, if (ret < 0) return ret; - chg_type = adp5061_chg_type[ADP5061_CHG_STATUS_1_CHG_STATUS(status1)]; - if (chg_type > ADP5061_CHG_FAST_CV) + chg_type = ADP5061_CHG_STATUS_1_CHG_STATUS(status1); + if (chg_type >= ARRAY_SIZE(adp5061_chg_type)) val->intval = POWER_SUPPLY_STATUS_UNKNOWN; else - val->intval = chg_type; + val->intval = adp5061_chg_type[chg_type]; return ret; } |