Re: [PATCH 1/2] ALSA: hda/conexant: Fix EAPD pin array overflow

Takashi Iwai <[email protected]>
Newsgroups org.kernel.vger.linux-sound,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Wed, 29 Jul 2026 09:09:34 +0200,
[email protected] wrote:
> 
> From: wangdicheng <[email protected]>
> 
> The bounds check in cx_auto_parse_eapd() happens after the write,
> so when a codec has more than 4 EAPD pins the 5th one gets written
> to eapds[4] which is past the end of the array and clobbers the
> adjacent dynamic_eapd field.


No, it checks right after the increment, then aborts the loop.  So any
overwrite won't happen.


Takashi

> 
> Signed-off-by: wangdicheng <[email protected]>
> ---
>  sound/hda/codecs/conexant.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/sound/hda/codecs/conexant.c b/sound/hda/codecs/conexant.c
> index 40da2832ba66..e7a2a073d22c 100644
> --- a/sound/hda/codecs/conexant.c
> +++ b/sound/hda/codecs/conexant.c
> @@ -100,9 +100,9 @@ static void cx_auto_parse_eapd(struct hda_codec *codec)
>  			continue;
>  		if (!(snd_hda_query_pin_caps(codec, nid) & AC_PINCAP_EAPD))
>  			continue;
> -		spec->eapds[spec->num_eapds++] = nid;
>  		if (spec->num_eapds >= ARRAY_SIZE(spec->eapds))
>  			break;
> +		spec->eapds[spec->num_eapds++] = nid;
>  	}
>  
>  	/* NOTE: below is a wild guess; if we have more than two EAPDs,
> -- 
> 2.25.1
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.