[PATCH] iio: pressure: bmp280: fix out-of-bounds access in sampling frequency lookup
Hui Su <[email protected]>
| Newsgroups | org.kernel.vger.linux-iio,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
The sampling frequency tables store each frequency as an integer part
and a fractional part in micro units. num_sampling_freq_avail is
initialized to the number of flattened integer elements because
read_avail() returns the table as a flat array.
bmp280_write_sampling_frequency(), however, indexes the same table as a
two-dimensional array and uses num_sampling_freq_avail as the number of
rows. This makes the lookup walk past the end of the table when an
unsupported sampling frequency is written.
Convert the flattened element count back to the number of rows before
iterating over the table.
Fixes: 10b40ffba2f9 ("iio: pressure: bmp280: Add more tunable config parameters for BMP380")
Cc: [email protected]
Signed-off-by: Hui Su <[email protected]>
---
drivers/iio/pressure/bmp280-core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/iio/pressure/bmp280-core.c b/drivers/iio/pressure/bmp280-core.c
index 990340a9b10c..ddd2de3c35ba 100644
--- a/drivers/iio/pressure/bmp280-core.c
+++ b/drivers/iio/pressure/bmp280-core.c
@@ -836,7 +836,8 @@ static int bmp280_write_sampling_frequency(struct bmp280_data *data,
int val, int val2)
{
const int (*avail)[2] = data->chip_info->sampling_freq_avail;
- const int n = data->chip_info->num_sampling_freq_avail;
+ const int n = data->chip_info->num_sampling_freq_avail /
+ ARRAY_SIZE(*avail);
int ret, prev;
int i;
--
2.43.0