From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754515AbdDOOwv (ORCPT ); Sat, 15 Apr 2017 10:52:51 -0400 Received: from mail-pg0-f67.google.com ([74.125.83.67]:36044 "EHLO mail-pg0-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752985AbdDOOwu (ORCPT ); Sat, 15 Apr 2017 10:52:50 -0400 From: Axel Lin To: Lee Jones Cc: Stefan Agner , Marcel Ziswiler , Mark Brown , Liam Girdwood , linux-kernel@vger.kernel.org, Axel Lin Subject: [PATCH RESEND] regulator: rn5t618: Fix out of bounds array access Date: Sat, 15 Apr 2017 22:52:39 +0800 Message-Id: <20170415145239.28880-1-axel.lin@ingics.com> X-Mailer: git-send-email 2.9.3 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The commit "regulator: rn5t618: Add RN5T567 PMIC support" added RN5T618_DCDC4 to the enum, then RN5T618_REG_NUM is also changed. So for rn5t618, there is out of bounds array access when checking regulators[i].name in the for loop. The number of regulators is different for rn5t567 and rn5t618, so we had better remove RN5T618_REG_NUM and get the correct num_regulators during probe instead. Fixes: ed6d362d8dbc ("regulator: rn5t618: Add RN5T567 PMIC support") Signed-off-by: Axel Lin --- RESEND: Correct subject line (remove double Fix) drivers/regulator/rn5t618-regulator.c | 8 ++++---- include/linux/mfd/rn5t618.h | 1 - 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/drivers/regulator/rn5t618-regulator.c b/drivers/regulator/rn5t618-regulator.c index 8d2819e..0c09143 100644 --- a/drivers/regulator/rn5t618-regulator.c +++ b/drivers/regulator/rn5t618-regulator.c @@ -85,14 +85,17 @@ static int rn5t618_regulator_probe(struct platform_device *pdev) struct regulator_config config = { }; struct regulator_dev *rdev; struct regulator_desc *regulators; + int num_regulators; int i; switch (rn5t618->variant) { case RN5T567: regulators = rn5t567_regulators; + num_regulators = ARRAY_SIZE(rn5t567_regulators); break; case RN5T618: regulators = rn5t618_regulators; + num_regulators = ARRAY_SIZE(rn5t618_regulators); break; default: return -EINVAL; @@ -101,10 +104,7 @@ static int rn5t618_regulator_probe(struct platform_device *pdev) config.dev = pdev->dev.parent; config.regmap = rn5t618->regmap; - for (i = 0; i < RN5T618_REG_NUM; i++) { - if (!regulators[i].name) - continue; - + for (i = 0; i < num_regulators; i++) { rdev = devm_regulator_register(&pdev->dev, ®ulators[i], &config); diff --git a/include/linux/mfd/rn5t618.h b/include/linux/mfd/rn5t618.h index e5a6cde..d7b3155 100644 --- a/include/linux/mfd/rn5t618.h +++ b/include/linux/mfd/rn5t618.h @@ -233,7 +233,6 @@ enum { RN5T618_LDO5, RN5T618_LDORTC1, RN5T618_LDORTC2, - RN5T618_REG_NUM, }; enum { -- 2.9.3