mirror of
https://github.com/torvalds/linux.git
synced 2026-09-25 17:42:03 +02:00
w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire
to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the
device. The downstream slave puts a length byte in buf[0]. The driver
then reads that many bytes into buf[1] with w1_f19_i2c_read().
buf[0] is controlled by the device and can be 0 to 255.
w1_f19_i2c_read() only rejects a zero count. The caller buffer is
I2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read
run past it, up to about 222 bytes out of bounds.
The SMBus core does check buf[0] against I2C_SMBUS_BLOCK_MAX. That
check runs after master_xfer returns. By then the write is already
done. i2c-algo-bit rejects an oversize length before it copies, and
returns -EPROTO.
Reject a length above I2C_SMBUS_BLOCK_MAX at both RECV_LEN sites, the
same way i2c-algo-bit does.
Fixes:
|
||
|---|---|---|
| .. | ||
| Kconfig | ||
| Makefile | ||
| w1_ds28e04.c | ||
| w1_ds28e17.c | ||
| w1_ds250x.c | ||
| w1_ds2405.c | ||
| w1_ds2406.c | ||
| w1_ds2408.c | ||
| w1_ds2413.c | ||
| w1_ds2423.c | ||
| w1_ds2430.c | ||
| w1_ds2431.c | ||
| w1_ds2433.c | ||
| w1_ds2438.c | ||
| w1_ds2780.c | ||
| w1_ds2780.h | ||
| w1_ds2781.c | ||
| w1_ds2781.h | ||
| w1_ds2805.c | ||
| w1_smem.c | ||
| w1_therm.c | ||