cmd64x: potential buffer overflow in cmd64x_program_timings()
authorDan Carpenter <dan.carpenter@oracle.com>
Tue, 7 Jan 2020 13:04:41 +0000 (16:04 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 28 Feb 2020 14:42:35 +0000 (15:42 +0100)
[ Upstream commit 117fcc3053606d8db5cef8821dca15022ae578bb ]

The "drive->dn" value is a u8 and it is controlled by root only, but
it could be out of bounds here so let's check.

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/ide/cmd64x.c

index b127ed6..9dde839 100644 (file)
@@ -65,6 +65,9 @@ static void cmd64x_program_timings(ide_drive_t *drive, u8 mode)
        struct ide_timing t;
        u8 arttim = 0;
 
+       if (drive->dn >= ARRAY_SIZE(drwtim_regs))
+               return;
+
        ide_timing_compute(drive, mode, &t, T, 0);
 
        /*