kwbimage: check return value of image_get_csk_index
authorHeinrich Schuchardt <xypron.glpk@gmx.de>
Tue, 17 Aug 2021 05:11:58 +0000 (07:11 +0200)
committerStefan Roese <sr@denx.de>
Wed, 1 Sep 2021 06:09:24 +0000 (08:09 +0200)
image_get_csk_index() may return -1 in case of an error. Don't use this
value as index.

This resolves Coverity CID 338488
Memory - illegal accesses  (NEGATIVE_RETURNS)

Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Reviewed-by: Stefan Roese <sr@denx.de>
Reviewed-by: Pali Rohár <pali@kernel.org>
tools/kwbimage.c

index b269488..aa865cc 100644 (file)
@@ -1087,7 +1087,7 @@ int kwb_sign_csk_with_kak(struct image_tool_params *params,
        int csk_idx = image_get_csk_index();
        struct sig_v1 tmp_sig;
 
-       if (csk_idx >= 16) {
+       if (csk_idx < 0 || csk_idx > 15) {
                fprintf(stderr, "Invalid CSK index %d\n", csk_idx);
                return 1;
        }