Re: [PATCH v2] iio: pressure: bmp280: fix out-of-bounds access in sampling frequency lookup
Jonathan Cameron <[email protected]>
| Newsgroups | org.kernel.vger.linux-iio,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <20260815225827.2ddb8397@jic23-huawei> |
On Tue, 11 Aug 2026 10:52:53 +0800 Hui Su <[email protected]> wrote: > The sampling frequency tables store each frequency as an integer part and > a fractional part in micro units. num_sampling_freq_avail is initialized > to the number of flattened integer elements because read_avail() returns > the table as a flat array. > > bmp280_write_sampling_frequency(), however, indexes the same table as a > two-dimensional array and uses num_sampling_freq_avail as the number of > rows. Convert the flattened element count back to the number of rows > before iterating over the table. > > Fixes: 10b40ffba2f9 ("iio: pressure: bmp280: Add more tunable config parameters for BMP380") > Cc: [email protected] > Signed-off-by: Hui Su <[email protected]> > Reviewed-by: Joshua Crofts <[email protected]> Hi Hui Su For future reference don't send a new version in reply to an older one. It rapidly looses all usefulness as the email threads get deeper and more complex. LGTM Applied to the fixes-togreg branch of iio.git Note I plan to rebase that once rc1 is out and a pull request will go upstream sometime after that. Thanks, Jonathan > --- > Changes in v2: > - Use plain 2 as the divisor, as suggested by Andy Shevchenko. > - Add Joshua Crofts' Reviewed-by tag. > Link: https://lore.kernel.org/lkml/[email protected]/ > > drivers/iio/pressure/bmp280-core.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/iio/pressure/bmp280-core.c b/drivers/iio/pressure/bmp280-core.c > index 990340a9b10c..dbe42233c81d 100644 > --- a/drivers/iio/pressure/bmp280-core.c > +++ b/drivers/iio/pressure/bmp280-core.c > @@ -836,7 +836,7 @@ static int bmp280_write_sampling_frequency(struct bmp280_data *data, > int val, int val2) > { > const int (*avail)[2] = data->chip_info->sampling_freq_avail; > - const int n = data->chip_info->num_sampling_freq_avail; > + const int n = data->chip_info->num_sampling_freq_avail / 2; > int ret, prev; > int i; >