mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-09-11 23:05:44 -04:00
iio: accel: bmc150: clamp the device-reported FIFO frame count
__bmc150_accel_fifo_flush() transfers the frame count the device reports in FIFO_STATUS into an on-stack buffer sized for BMC150_ACCEL_FIFO_LENGTH (32) samples, but the count is masked to 7 bits (0..127) and the optional caller budget does not bound the flush-all path. A device, or an attacker on the I2C/SPI bus, reporting up to 127 frames overflows the buffer by up to 570 bytes: a stack out-of-bounds write. Clamp the count to BMC150_ACCEL_FIFO_LENGTH before the transfer, mirroring the clamp already applied in bmc150_accel_set_watermark(). Conforming hardware reports at most that many frames and is unaffected. Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
This commit is contained in:
committed by
Jonathan Cameron
parent
e8de771d80
commit
d2a4411137
@@ -988,8 +988,10 @@ static int __bmc150_accel_fifo_flush(struct iio_dev *indio_dev,
|
||||
do_div(sample_period, count);
|
||||
tstamp = data->timestamp - (count - 1) * sample_period;
|
||||
|
||||
if (samples && count > samples)
|
||||
count = samples;
|
||||
if (samples)
|
||||
count = min3(count, samples, BMC150_ACCEL_FIFO_LENGTH);
|
||||
else
|
||||
count = min(count, BMC150_ACCEL_FIFO_LENGTH);
|
||||
|
||||
ret = bmc150_accel_fifo_transfer(data, (u8 *)buffer, count);
|
||||
if (ret)
|
||||
|
||||
Reference in New Issue
Block a user