Re: [PATCH v2] iio: pressure: bmp280: fix out-of-bounds access in sampling frequency lookup

Jonathan Cameron <[email protected]>
Newsgroups gmane.linux.kernel.iio,gmane.linux.kernel,gmane.linux.kernel.stable
Message-ID <20260815225827.2ddb8397@jic23-huawei>
On Tue, 11 Aug 2026 10:52:53 +0800
Hui Su <sh_def-9Onoh4P/[email protected]> wrote:

> The sampling frequency tables store each frequency as an integer part and
> a fractional part in micro units. num_sampling_freq_avail is initialized
> to the number of flattened integer elements because read_avail() returns
> the table as a flat array.
> 
> bmp280_write_sampling_frequency(), however, indexes the same table as a
> two-dimensional array and uses num_sampling_freq_avail as the number of
> rows. Convert the flattened element count back to the number of rows
> before iterating over the table.
> 
> Fixes: 10b40ffba2f9 ("iio: pressure: bmp280: Add more tunable config parameters for BMP380")
> Cc: [email protected]
> Signed-off-by: Hui Su <sh_def-9Onoh4P/[email protected]>
> Reviewed-by: Joshua Crofts <[email protected]>

Hi Hui Su

For future reference don't send a new version in reply to an older one. It rapidly looses
all usefulness as the email threads get deeper and more complex.

LGTM Applied to the fixes-togreg branch of iio.git

Note I plan to rebase that once rc1 is out and a pull request will go upstream
sometime after that.

Thanks,

Jonathan

> ---
> Changes in v2:
> - Use plain 2 as the divisor, as suggested by Andy Shevchenko.
> - Add Joshua Crofts' Reviewed-by tag.
> Link: https://lore.kernel.org/lkml/20260805074127.473731-1-sh_def-9Onoh4P/[email protected]/
> 
>  drivers/iio/pressure/bmp280-core.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/iio/pressure/bmp280-core.c b/drivers/iio/pressure/bmp280-core.c
> index 990340a9b10c..dbe42233c81d 100644
> --- a/drivers/iio/pressure/bmp280-core.c
> +++ b/drivers/iio/pressure/bmp280-core.c
> @@ -836,7 +836,7 @@ static int bmp280_write_sampling_frequency(struct bmp280_data *data,
>  					   int val, int val2)
>  {
>  	const int (*avail)[2] = data->chip_info->sampling_freq_avail;
> -	const int n = data->chip_info->num_sampling_freq_avail;
> +	const int n = data->chip_info->num_sampling_freq_avail / 2;
>  	int ret, prev;
>  	int i;
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.