mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
usb: typec: ucsi: displayport: Fix OOB altmode array index
The UCSI displayport driver indexes the connector's port altmode array
with the GET_CURRENT_CAM response after checking it is not 0xff. The
port altmode array is UCSI_MAX_ALTMODES elements long. If the PPM
returns an invalid GET_CURRENT_CAM response above UCSI_MAX_ALTMODES and
not equal to 0xff, the kernel may crash with an array index OOB error.
Update the UCSI displayport driver to verify the current cam is less
than UCSI_MAX_ALTMODES before accessing the port altmode array.
Fixes: af8622f6a5 ("usb: typec: ucsi: Support for DisplayPort alt mode")
Cc: stable@vger.kernel.org
Signed-off-by: Jameson Thies <jthies@google.com>
Reviewed-by: Benson Leung <bleung@chromium.org>
Link: https://patch.msgid.link/20260825234545.2076049-1-jthies@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
ff44dfb03a
commit
04cec690b1
|
|
@ -74,7 +74,7 @@ static int ucsi_displayport_enter(struct typec_altmode *alt, u32 *vdo)
|
|||
cur = 0xff;
|
||||
}
|
||||
|
||||
if (cur != 0xff) {
|
||||
if (cur < UCSI_MAX_ALTMODES) {
|
||||
ret = dp->con->port_altmode[cur] == alt ? 0 : -EBUSY;
|
||||
goto err_unlock;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user