usb: xhci-mtk: fix issue of out-of-bounds array access
authorChunfeng Yun <chunfeng.yun@mediatek.com>
Tue, 17 Aug 2021 08:36:25 +0000 (16:36 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 26 Aug 2021 11:39:20 +0000 (13:39 +0200)
Bus bandwidth array access is based on esit, increase one
will cause out-of-bounds issue; for example, when esit is
XHCI_MTK_MAX_ESIT, will overstep boundary.

Fixes: 7c986fbc16ae ("usb: xhci-mtk: get the microframe boundary for ESIT")
Cc: <stable@vger.kernel.org>
Reported-by: Stan Lu <stan.lu@mediatek.com>
Signed-off-by: Chunfeng Yun <chunfeng.yun@mediatek.com>
Link: https://lore.kernel.org/r/1629189389-18779-5-git-send-email-chunfeng.yun@mediatek.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/usb/host/xhci-mtk-sch.c

index cffcaf4..0bb1a62 100644 (file)
@@ -575,10 +575,12 @@ static u32 get_esit_boundary(struct mu3h_sch_ep_info *sch_ep)
        u32 boundary = sch_ep->esit;
 
        if (sch_ep->sch_tt) { /* LS/FS with TT */
-               /* tune for CS */
-               if (sch_ep->ep_type != ISOC_OUT_EP)
-                       boundary++;
-               else if (boundary > 1) /* normally esit >= 8 for FS/LS */
+               /*
+                * tune for CS, normally esit >= 8 for FS/LS,
+                * not add one for other types to avoid access array
+                * out of boundary
+                */
+               if (sch_ep->ep_type == ISOC_OUT_EP && boundary > 1)
                        boundary--;
        }