mirror of
https://github.com/torvalds/linux.git
synced 2026-05-28 17:13:52 +02:00
iio: temperature: tmp006: fix information leak in triggered buffer
The 'scan' local struct is used to push data to user space from a
triggered buffer, but it has a hole between the two 16-bit data channels
and the timestamp. This hole is never initialized.
Initialize the struct to zero before using it to avoid pushing
uninitialized information to userspace.
Fixes: 91f75ccf9f ("iio: temperature: tmp006: add triggered buffer support")
Signed-off-by: Javier Carrasco <javier.carrasco.cruz@gmail.com>
Link: https://patch.msgid.link/20241204-iio_memset_scan_holes-v2-1-3f941592a76d@gmail.com
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
This commit is contained in:
parent
64f43895b4
commit
2f43d5200c
|
|
@ -252,6 +252,8 @@ static irqreturn_t tmp006_trigger_handler(int irq, void *p)
|
|||
} scan;
|
||||
s32 ret;
|
||||
|
||||
memset(&scan, 0, sizeof(scan));
|
||||
|
||||
ret = i2c_smbus_read_word_data(data->client, TMP006_VOBJECT);
|
||||
if (ret < 0)
|
||||
goto err;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user