mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] crypto: qat - (qat_420xx) fix off by one in uof_get_name()
@ 2024-09-28 10:05 Dan Carpenter
  2024-10-01 11:05 ` Cabiddu, Giovanni
  2024-10-05  5:38 ` Herbert Xu
  0 siblings, 2 replies; 3+ messages in thread
From: Dan Carpenter @ 2024-09-28 10:05 UTC (permalink / raw)
  To: Jie Wang
  Cc: Giovanni Cabiddu, Herbert Xu, David S. Miller, Damian Muszynski,
	Tero Kristo, Shashank Gupta, Lucas Segarra Fernandez, Dong Xie,
	qat-linux, linux-crypto, linux-kernel, kernel-janitors

This is called from uof_get_name_420xx() where "num_objs" is the
ARRAY_SIZE() of fw_objs[].  The > needs to be >= to prevent an out of
bounds access.

Fixes: fcf60f4bcf54 ("crypto: qat - add support for 420xx devices")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
---
 drivers/crypto/intel/qat/qat_420xx/adf_420xx_hw_data.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/crypto/intel/qat/qat_420xx/adf_420xx_hw_data.c b/drivers/crypto/intel/qat/qat_420xx/adf_420xx_hw_data.c
index 78f0ea49254d..9faef33e54bd 100644
--- a/drivers/crypto/intel/qat/qat_420xx/adf_420xx_hw_data.c
+++ b/drivers/crypto/intel/qat/qat_420xx/adf_420xx_hw_data.c
@@ -375,7 +375,7 @@ static const char *uof_get_name(struct adf_accel_dev *accel_dev, u32 obj_num,
 	else
 		id = -EINVAL;
 
-	if (id < 0 || id > num_objs)
+	if (id < 0 || id >= num_objs)
 		return NULL;
 
 	return fw_objs[id];
-- 
2.45.2


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] crypto: qat - (qat_420xx) fix off by one in uof_get_name()
  2024-09-28 10:05 [PATCH] crypto: qat - (qat_420xx) fix off by one in uof_get_name() Dan Carpenter
@ 2024-10-01 11:05 ` Cabiddu, Giovanni
  2024-10-05  5:38 ` Herbert Xu
  1 sibling, 0 replies; 3+ messages in thread
From: Cabiddu, Giovanni @ 2024-10-01 11:05 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: Jie Wang, Herbert Xu, David S. Miller, Damian Muszynski,
	Tero Kristo, Shashank Gupta, Lucas Segarra Fernandez, Dong Xie,
	qat-linux, linux-crypto, linux-kernel, kernel-janitors

On Sat, Sep 28, 2024 at 01:05:01PM +0300, Dan Carpenter wrote:
> This is called from uof_get_name_420xx() where "num_objs" is the
> ARRAY_SIZE() of fw_objs[].  The > needs to be >= to prevent an out of
> bounds access.
> 
> Fixes: fcf60f4bcf54 ("crypto: qat - add support for 420xx devices")
> Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Acked-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] crypto: qat - (qat_420xx) fix off by one in uof_get_name()
  2024-09-28 10:05 [PATCH] crypto: qat - (qat_420xx) fix off by one in uof_get_name() Dan Carpenter
  2024-10-01 11:05 ` Cabiddu, Giovanni
@ 2024-10-05  5:38 ` Herbert Xu
  1 sibling, 0 replies; 3+ messages in thread
From: Herbert Xu @ 2024-10-05  5:38 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: Jie Wang, Giovanni Cabiddu, David S. Miller, Damian Muszynski,
	Tero Kristo, Shashank Gupta, Lucas Segarra Fernandez, Dong Xie,
	qat-linux, linux-crypto, linux-kernel, kernel-janitors

On Sat, Sep 28, 2024 at 01:05:01PM +0300, Dan Carpenter wrote:
> This is called from uof_get_name_420xx() where "num_objs" is the
> ARRAY_SIZE() of fw_objs[].  The > needs to be >= to prevent an out of
> bounds access.
> 
> Fixes: fcf60f4bcf54 ("crypto: qat - add support for 420xx devices")
> Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
> ---
>  drivers/crypto/intel/qat/qat_420xx/adf_420xx_hw_data.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

Patch applied.  Thanks.
-- 
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2024-10-05  5:38 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-09-28 10:05 [PATCH] crypto: qat - (qat_420xx) fix off by one in uof_get_name() Dan Carpenter
2024-10-01 11:05 ` Cabiddu, Giovanni
2024-10-05  5:38 ` Herbert Xu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®