diff options
author | Dan Carpenter <dan.carpenter@oracle.com> | 2020-01-07 16:04:41 +0300 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2020-01-20 13:38:27 +0100 |
commit | 117fcc3053606d8db5cef8821dca15022ae578bb (patch) | |
tree | 412f04483800c0222cfdf95b728af0aed17759ee /drivers/ide | |
parent | 0fdeae5036086aa214a45e598c079a3334bc15c3 (diff) | |
download | linux-stable-117fcc3053606d8db5cef8821dca15022ae578bb.tar.gz linux-stable-117fcc3053606d8db5cef8821dca15022ae578bb.tar.bz2 linux-stable-117fcc3053606d8db5cef8821dca15022ae578bb.zip |
cmd64x: potential buffer overflow in cmd64x_program_timings()
The "drive->dn" value is a u8 and it is controlled by root only, but
it could be out of bounds here so let's check.
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'drivers/ide')
-rw-r--r-- | drivers/ide/cmd64x.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/drivers/ide/cmd64x.c b/drivers/ide/cmd64x.c index a1898e11b04e..943bf944bf72 100644 --- a/drivers/ide/cmd64x.c +++ b/drivers/ide/cmd64x.c @@ -66,6 +66,9 @@ static void cmd64x_program_timings(ide_drive_t *drive, u8 mode) struct ide_timing t; u8 arttim = 0; + if (drive->dn >= ARRAY_SIZE(drwtim_regs)) + return; + ide_timing_compute(drive, mode, &t, T, 0); /* |