Re: [PATCH] hwmon: (nct6775-core) Fix number of temperature registers for NCT6116

Florian Bezdeka <[email protected]>
Newsgroups org.kernel.vger.linux-hwmon
Message-ID <[email protected]>
On Wed, 2026-07-22 at 07:28 -0700, Guenter Roeck wrote:
> Unlike NCT6106, NCT6116 only has three temperature registers, and with
> it only three temperature source and temperature source configuration
> registers. The register addresses match those of NCT6106 and can be
> re-used.
> 
> The code used a separate array to list the temperature source registers
> for NCT6116, but used the size of the NCT6106 register array to set
> the number of registers. The NCT6106 register array provides six addresses,
> while the temperature source register array for NCT6116 only provides three
> addresses. This causes a KASAN report.
> 
> BUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775]
> Read of size 2 at addr ffffffffc19561a6 by task modprobe/954
> ...
> Call Trace:
>  dump_stack+0x7d/0xa7
>  print_address_description.constprop.0+0x1c/0x220
>  ? __kasan_kmalloc.constprop.0+0xc9/0xd0
>  ? __kmalloc_node_track_caller+0x194/0x5b0
>  ? nct6775_probe+0x936/0x46f0 [nct6775]
>  ? nct6775_probe+0x936/0x46f0 [nct6775]
> ...
> 
> Fix the problem by hard-coding the number of temperature and temperature
> configuration registers to three for NCT6116. Drop the unnecessary
> NCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE.

Thanks a lot for taking over and the super fast response/fix. Highly
appreciated!

Have you checked how far we get with the auto-stable apply process? I'm
expecting that 5.10 (and maybe 5.15 in addition) will need some manual
backporting. Happy to help there, just let me know.

> 
> Reported-by: Florian Bezdeka <[email protected]>
> Closes: https://lore.kernel.org/linux-hwmon/[email protected]/T/#t
> Fixes: 29c7cb485b32 ("hwmon: (nct6775) Integrate new model nct6116")
> Cc: Björn Gerhart <[email protected]>
> Signed-off-by: Guenter Roeck <[email protected]>

Reviewed-by: Florian Bezdeka <[email protected]>

> ---
>  drivers/hwmon/nct6775-core.c | 8 +++-----
>  1 file changed, 3 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/hwmon/nct6775-core.c b/drivers/hwmon/nct6775-core.c
> index d668dc390def..51253acff4b0 100644
> --- a/drivers/hwmon/nct6775-core.c
> +++ b/drivers/hwmon/nct6775-core.c
> @@ -846,8 +846,6 @@ static const u16 NCT6116_FAN_PULSE_SHIFT[] = { 0, 2, 4, 6, 6 };
>  static const u16 NCT6116_REG_PWM[] = { 0x119, 0x129, 0x139, 0x199, 0x1a9 };
>  static const u16 NCT6116_REG_FAN_MODE[] = { 0x113, 0x123, 0x133, 0x193, 0x1a3 };
>  static const u16 NCT6116_REG_TEMP_SEL[] = { 0x110, 0x120, 0x130, 0x190, 0x1a0 };
> -static const u16 NCT6116_REG_TEMP_SOURCE[] = {
> -	0xb0, 0xb1, 0xb2 };
>  
>  static const u16 NCT6116_REG_CRITICAL_TEMP[] = {
>  	0x11a, 0x12a, 0x13a, 0x19a, 0x1aa };
> @@ -3652,7 +3650,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
>  		  = NCT6106_CRITICAL_PWM_ENABLE_MASK;
>  		data->REG_CRITICAL_PWM = NCT6116_REG_CRITICAL_PWM;
>  		data->REG_TEMP_OFFSET = NCT6106_REG_TEMP_OFFSET;
> -		data->REG_TEMP_SOURCE = NCT6116_REG_TEMP_SOURCE;
> +		data->REG_TEMP_SOURCE = NCT6106_REG_TEMP_SOURCE;
>  		data->REG_TEMP_SEL = NCT6116_REG_TEMP_SEL;
>  		data->REG_WEIGHT_TEMP_SEL = NCT6106_REG_WEIGHT_TEMP_SEL;
>  		data->REG_WEIGHT_TEMP[0] = NCT6106_REG_WEIGHT_TEMP_STEP;
> @@ -3666,13 +3664,13 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
>  
>  		reg_temp = NCT6106_REG_TEMP;
>  		reg_temp_mon = NCT6106_REG_TEMP_MON;
> -		num_reg_temp = ARRAY_SIZE(NCT6106_REG_TEMP);
> +		num_reg_temp = 3;
>  		num_reg_temp_mon = ARRAY_SIZE(NCT6106_REG_TEMP_MON);
>  		num_reg_tsi_temp = ARRAY_SIZE(NCT6116_REG_TSI_TEMP);
>  		reg_temp_over = NCT6106_REG_TEMP_OVER;
>  		reg_temp_hyst = NCT6106_REG_TEMP_HYST;
>  		reg_temp_config = NCT6106_REG_TEMP_CONFIG;
> -		num_reg_temp_config = ARRAY_SIZE(NCT6106_REG_TEMP_CONFIG);
> +		num_reg_temp_config = 3;
>  		reg_temp_alternate = NCT6106_REG_TEMP_ALTERNATE;
>  		reg_temp_crit = NCT6106_REG_TEMP_CRIT;
>  		reg_temp_crit_l = NCT6106_REG_TEMP_CRIT_L;
> -- 
> 2.45.2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.