[PATCH 1/2] ALSA: hda/conexant: Fix EAPD pin array overflow

[email protected]
Newsgroups org.kernel.vger.linux-sound,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
From: wangdicheng <[email protected]>

The bounds check in cx_auto_parse_eapd() happens after the write,
so when a codec has more than 4 EAPD pins the 5th one gets written
to eapds[4] which is past the end of the array and clobbers the
adjacent dynamic_eapd field.

Swap the check and the write.

Signed-off-by: wangdicheng <[email protected]>
---
 sound/hda/codecs/conexant.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/hda/codecs/conexant.c b/sound/hda/codecs/conexant.c
index 40da2832ba66..e7a2a073d22c 100644
--- a/sound/hda/codecs/conexant.c
+++ b/sound/hda/codecs/conexant.c
@@ -100,9 +100,9 @@ static void cx_auto_parse_eapd(struct hda_codec *codec)
 			continue;
 		if (!(snd_hda_query_pin_caps(codec, nid) & AC_PINCAP_EAPD))
 			continue;
-		spec->eapds[spec->num_eapds++] = nid;
 		if (spec->num_eapds >= ARRAY_SIZE(spec->eapds))
 			break;
+		spec->eapds[spec->num_eapds++] = nid;
 	}
 
 	/* NOTE: below is a wild guess; if we have more than two EAPDs,
-- 
2.25.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.