usb: atm: ueagle-atm: fix array-index-out-of-bounds in uea_bind()

Add a bounds check on the global variable modem_index before
using it as an index in sync_wait[] array whose size is NB_MODEM.

Cc: stable+noautosel@kernel.org # untested fix to a driver init path race
Reported-by: syzbot+92f5bf49bf4ac75223ca@syzkaller.appspotmail.com
Tested-by: syzbot+92f5bf49bf4ac75223ca@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=92f5bf49bf4ac75223ca
Signed-off-by: Subasri S <subasris1210@gmail.com>
Link: https://patch.msgid.link/20260802-usb-ueagble-atm-v1-1-340f085b04aa@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
Subasri S 2026-08-02 11:59:24 +05:30 committed by Jakub Kicinski
parent 762137ff74
commit 37a5e12011

View File

@ -2463,7 +2463,8 @@ static int uea_bind(struct usbatm_data *usbatm, struct usb_interface *intf,
if (ifnum != UEA_INTR_IFACE_NO)
return -ENODEV;
usbatm->flags = (sync_wait[modem_index] ? 0 : UDSL_SKIP_HEAVY_INIT);
usbatm->flags = (modem_index < NB_MODEM && sync_wait[modem_index]) ?
0 : UDSL_SKIP_HEAVY_INIT;
/* interface 1 is for outbound traffic */
ret = claim_interface(usb, usbatm, UEA_US_IFACE_NO);