Commit c51fa6be authored by zhili.liu's avatar zhili.liu Committed by Guo Mengqi
Browse files

iio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC

stable inclusion
from stable-v5.10.210
commit 36a49290d7e6d554020057a409747a092b1d3b56
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I9E2FC

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=36a49290d7e6d554020057a409747a092b1d3b56



--------------------------------

commit 792595bab4925aa06532a14dd256db523eb4fa5e upstream.

Recently, we encounter kernel crash in function rm3100_common_probe
caused by out of bound access of array rm3100_samp_rates (because of
underlying hardware failures). Add boundary check to prevent out of
bound access.

Fixes: 121354b2 ("iio: magnetometer: Add driver support for PNI RM3100")
Suggested-by: default avatarZhouyi Zhou <zhouzhouyi@gmail.com>
Signed-off-by: default avatarzhili.liu <zhili.liu@ucas.com.cn>
Link: https://lore.kernel.org/r/1704157631-3814-1-git-send-email-zhouzhouyi@gmail.com


Cc: <Stable@vger.kernel.org>
Signed-off-by: default avatarJonathan Cameron <Jonathan.Cameron@huawei.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: default avatarWang Hai <wanghai38@huawei.com>
parent 719747ca
Loading
Loading
Loading
Loading
+8 −2
Original line number Diff line number Diff line
@@ -538,6 +538,7 @@ int rm3100_common_probe(struct device *dev, struct regmap *regmap, int irq)
	struct rm3100_data *data;
	unsigned int tmp;
	int ret;
	int samp_rate_index;

	indio_dev = devm_iio_device_alloc(dev, sizeof(*data));
	if (!indio_dev)
@@ -596,9 +597,14 @@ int rm3100_common_probe(struct device *dev, struct regmap *regmap, int irq)
	ret = regmap_read(regmap, RM3100_REG_TMRC, &tmp);
	if (ret < 0)
		return ret;

	samp_rate_index = tmp - RM3100_TMRC_OFFSET;
	if (samp_rate_index < 0 || samp_rate_index >=  RM3100_SAMP_NUM) {
		dev_err(dev, "The value read from RM3100_REG_TMRC is invalid!\n");
		return -EINVAL;
	}
	/* Initializing max wait time, which is double conversion time. */
	data->conversion_time = rm3100_samp_rates[tmp - RM3100_TMRC_OFFSET][2]
				* 2;
	data->conversion_time = rm3100_samp_rates[samp_rate_index][2] * 2;

	/* Cycle count values may not be what we want. */
	if ((tmp - RM3100_TMRC_OFFSET) == 0)