projects
/
platform
/
kernel
/
linux-starfive.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
0fdeae5
)
cmd64x: potential buffer overflow in cmd64x_program_timings()
author
Dan Carpenter
<dan.carpenter@oracle.com>
Tue, 7 Jan 2020 13:04:41 +0000
(16:04 +0300)
committer
David S. Miller
<davem@davemloft.net>
Mon, 20 Jan 2020 12:38:27 +0000
(13:38 +0100)
The "drive->dn" value is a u8 and it is controlled by root only, but
it could be out of bounds here so let's check.
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
drivers/ide/cmd64x.c
patch
|
blob
|
history
diff --git
a/drivers/ide/cmd64x.c
b/drivers/ide/cmd64x.c
index
a1898e1
..
943bf94
100644
(file)
--- a/
drivers/ide/cmd64x.c
+++ b/
drivers/ide/cmd64x.c
@@
-66,6
+66,9
@@
static void cmd64x_program_timings(ide_drive_t *drive, u8 mode)
struct ide_timing t;
u8 arttim = 0;
+ if (drive->dn >= ARRAY_SIZE(drwtim_regs))
+ return;
+
ide_timing_compute(drive, mode, &t, T, 0);
/*