From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755581AbbHLKfY (ORCPT ); Wed, 12 Aug 2015 06:35:24 -0400 Received: from fallback6.mail.ru ([94.100.181.147]:55481 "EHLO fallback6.mail.ru" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751280AbbHLKfU (ORCPT ); Wed, 12 Aug 2015 06:35:20 -0400 X-Greylist: delayed 2473 seconds by postgrey-1.27 at vger.kernel.org; Wed, 12 Aug 2015 06:35:19 EDT From: =?UTF-8?B?QWxleGFuZGVyIFNoaXlhbg==?= To: =?UTF-8?B?Y2FudG9uYQ==?= Cc: =?UTF-8?B?SmlyaSBTbGFieQ==?= , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, =?UTF-8?B?R3JlZyBLcm9haC1IYXJ0bWFu?= Subject: =?UTF-8?B?UmU6IFtQQVRDSCB2Ml0gc2VyaWFsOiBtYXgzMTB4OiBGaXggb3V0IG9mIGJv?= =?UTF-8?B?dW5kcyBhY2Nlc3M=?= MIME-Version: 1.0 X-Mailer: Mail.Ru Mailer 1.0 X-Originating-IP: [217.119.30.118] Date: Wed, 12 Aug 2015 12:46:05 +0300 Reply-To: =?UTF-8?B?QWxleGFuZGVyIFNoaXlhbg==?= X-Priority: 3 (Normal) Message-ID: <1439372765.705411926@f362.i.mail.ru> Content-Type: text/plain; charset=utf-8 X-Mras: Ok X-Spam: undefined In-Reply-To: References: <1439364125-19422-1-git-send-email-cantona@cantona.net> Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Transfer-Encoding: 8bit X-MIME-Autoconverted: from base64 to 8bit by mail.home.local id t7CAZUMM017641 > Среда, 12 августа 2015, 15:36 +08:00 от cantona : > > > added Alexander Shiyan < shc_work@mail.ru >. > > On 12 August 2015 at 15:22, Su Kang Yin < cantona@cantona.net > wrote: > >Max310x driver supports up to 4 UART devices but array size of > >"struct max310x_one" is set to 1. That leads to out of bounds > >access on UART port registration. > > > >This patch fixed it by increase the array size to 4 which is > >maximum supported UART. > > > >Signed-off-by: Su Kang Yin < cantona@cantona.net > > >--- ... This seems incorrect. The number of ports is allocated dynamically by: ... /* Alloc port structure */ s = devm_kzalloc(dev, sizeof(*s) + sizeof(struct max310x_one) * devtype->nr, GFP_KERNEL); ... Thanks. --- {.n++%ݶw{.n+{G{ayʇڙ,jfhz_(階ݢj"mG?&~iOzv^m ?I