mirror of
https://github.com/torvalds/linux.git
synced 2026-09-24 06:24:02 +02:00
iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show
ad3552r_hs_show_data_source_avail() formats the available data source
names into a 128-byte stack buffer, but bounds each scnprintf() with
PAGE_SIZE instead of the buffer size, so the bound does not protect
the destination at all.
This cannot overflow today - dbgfs_attr_source[] has two entries,
"normal" and "ramp-16bit", 18 bytes formatted - but the bound stops
protecting the stack the day the table grows. Use sizeof(buf) so the
bound matches the destination.
Found by smatch:
drivers/iio/dac/ad3552r-hs.c:593 ad3552r_hs_show_data_source_avail()
error: scnprintf() 'buf[len]' too small (128 vs 4096)
Fixes: b1c5d68ea6 ("iio: dac: ad3552r-hs: add support for internal ramp")
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
This commit is contained in:
parent
739aac8763
commit
f2c5c76306
|
|
@ -591,7 +591,7 @@ static ssize_t ad3552r_hs_show_data_source_avail(struct file *f,
|
|||
int i;
|
||||
|
||||
for (i = 0; i < ARRAY_SIZE(dbgfs_attr_source); i++) {
|
||||
len += scnprintf(buf + len, PAGE_SIZE - len, "%s ",
|
||||
len += scnprintf(buf + len, sizeof(buf) - len, "%s ",
|
||||
dbgfs_attr_source[i]);
|
||||
}
|
||||
buf[len - 1] = '\n';
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user