mirror of
https://github.com/torvalds/linux.git
synced 2026-10-08 11:36:02 +02:00
In encode_message() the per-transaction lower-bound check compares
trans_hdr->len against sizeof(trans_hdr), i.e. the size of the pointer,
instead of sizeof(*trans_hdr), the size of struct qaic_manage_trans_hdr.
Every other length check in this file (encode_message() at the loop
guard, decode_message(), etc.) correctly uses sizeof(*trans_hdr), so
this is an inconsistency. On 64-bit builds the pointer and the struct
are both 8 bytes, so the check is correct by coincidence and there is
no behavioural change. On 32-bit builds the pointer is 4 bytes, which
weakens the minimum-length check below the 8-byte header size.
Use sizeof(*trans_hdr) so the check validates against the actual
transaction header size on all builds.
Fixes:
|
||
|---|---|---|
| .. | ||
| Kconfig | ||
| Makefile | ||
| mhi_controller.c | ||
| mhi_controller.h | ||
| qaic_control.c | ||
| qaic_data.c | ||
| qaic_debugfs.c | ||
| qaic_debugfs.h | ||
| qaic_drv.c | ||
| qaic_ras.c | ||
| qaic_ras.h | ||
| qaic_ssr.c | ||
| qaic_ssr.h | ||
| qaic_sysfs.c | ||
| qaic_timesync.c | ||
| qaic_timesync.h | ||
| qaic.h | ||
| sahara.c | ||
| sahara.h | ||