mirror of
https://github.com/torvalds/linux.git
synced 2026-09-14 16:10:02 +02:00
usb: atm: ueagle-atm: fix array-index-out-of-bounds in uea_bind()
Add a bounds check on the global variable modem_index before using it as an index in sync_wait[] array whose size is NB_MODEM. Cc: stable+noautosel@kernel.org # untested fix to a driver init path race Reported-by: syzbot+92f5bf49bf4ac75223ca@syzkaller.appspotmail.com Tested-by: syzbot+92f5bf49bf4ac75223ca@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=92f5bf49bf4ac75223ca Signed-off-by: Subasri S <subasris1210@gmail.com> Link: https://patch.msgid.link/20260802-usb-ueagble-atm-v1-1-340f085b04aa@gmail.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
762137ff74
commit
37a5e12011
|
|
@ -2463,7 +2463,8 @@ static int uea_bind(struct usbatm_data *usbatm, struct usb_interface *intf,
|
|||
if (ifnum != UEA_INTR_IFACE_NO)
|
||||
return -ENODEV;
|
||||
|
||||
usbatm->flags = (sync_wait[modem_index] ? 0 : UDSL_SKIP_HEAVY_INIT);
|
||||
usbatm->flags = (modem_index < NB_MODEM && sync_wait[modem_index]) ?
|
||||
0 : UDSL_SKIP_HEAVY_INIT;
|
||||
|
||||
/* interface 1 is for outbound traffic */
|
||||
ret = claim_interface(usb, usbatm, UEA_US_IFACE_NO);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user