All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Marcelo Schmitt" <marcelo.schmitt@analog.com>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v2 01/15] iio: adc: ad4134: Sign extend sample data
Date: Tue, 15 Sep 2026 19:28:11 +0000	[thread overview]
Message-ID: <20260915192811.B9CE21F000FF@smtp.kernel.org> (raw)
In-Reply-To: <7083358e62e3edfeeba0201aefd8d3195ee951d0.1789494473.git.marcelo.schmitt@analog.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] iio: adc: ad4134: info leak via uninitialized sample in ad4134_data_read()
--

commit 56b8f43cabdc9a50d1d532dbfddf01a627e253d4
Author: Marcelo Schmitt <marcelo.schmitt@analog.com>

iio: adc: ad4134: Sign extend sample data

Sign extend ADC sample data for correct delivery of negative ADC input
difference.

> diff --git a/drivers/iio/adc/ad4134.c b/drivers/iio/adc/ad4134.c
> index 0490218bb0e9b..7d40c0521bb3f 100644
> --- a/drivers/iio/adc/ad4134.c
> +++ b/drivers/iio/adc/ad4134.c
> @@ -172,6 +172,7 @@ static int ad4134_data_read(struct ad4134_state *st, unsigned int reg,
>  			    unsigned int *val)
>  {
>  	unsigned int i;
> +	u32 sample;
>  	int ret;
>  
>  	/*

[ ... ]

> @@ -196,8 +197,9 @@ static int ad4134_data_read(struct ad4134_state *st, unsigned int reg,
>  		 * Clock out data from all channels to avoid that.
>  		 */
>  		if (i == AD4134_VREG_CH(reg))
> -			*val = get_unaligned_be24(st->rx_buf);
> +			sample = get_unaligned_be24(st->rx_buf);
>  	}
> +	*val = sign_extend32(sample, AD4134_CHAN_PRECISION_BITS - 1);

[Severity: High]
Does this code leak uninitialized stack memory to userspace?

If a privileged user reads register 0x54 via the IIO debugfs
direct_reg_access file, ad4134_data_read() is invoked with reg=0x54. This is
possible because of a pre-existing off-by-one error in the regmap
configuration (where AD4134_CH_VREG(AD4134_NUM_CHANNELS) evaluates to 0x54)
that allows read access to this virtual register.

Because the loop index 'i' only iterates up to 3, the condition
'i == AD4134_VREG_CH(0x54)' is never met and 'sample' is left uninitialized.
The newly introduced code then unconditionally sign-extends this uninitialized
memory and writes it back to '*val', which is then returned to the user.

>  
>  	return 0;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1789494473.git.marcelo.schmitt@analog.com?part=1

  reply	other threads:[~2026-09-15 19:28 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 19:11 [PATCH v2 00/15] iio: adc: ad4134: Enable greater sample rate data capture Marcelo Schmitt
2026-09-15 19:11 ` [PATCH v2 01/15] iio: adc: ad4134: Sign extend sample data Marcelo Schmitt
2026-09-15 19:28   ` sashiko-bot [this message]
2026-09-21  1:50   ` Jonathan Cameron
2026-09-15 19:12 ` [PATCH v2 02/15] iio: Fix typo in vendor name Marcelo Schmitt
2026-09-21  1:50   ` Jonathan Cameron
2026-09-15 19:12 ` [PATCH v2 03/15] iio: adc: ad4134: Drop import to empty name space Marcelo Schmitt
2026-09-21  1:19   ` Jonathan Cameron
2026-09-15 19:13 ` [PATCH v2 04/15] iio: adc: ad4134: Update include list to comply with IWYU principles Marcelo Schmitt
2026-09-15 19:13 ` [PATCH v2 05/15] iio: adc: ad4134: Serialize single-read operations Marcelo Schmitt
2026-09-15 19:13 ` [PATCH v2 06/15] iio: adc: ad4134: Run shorter transfers when CRC is disabled Marcelo Schmitt
2026-09-15 19:14 ` [PATCH v2 07/15] iio: adc: ad4134: Add support for digital filter type selection Marcelo Schmitt
2026-09-15 19:14 ` [PATCH v2 08/15] iio: adc: ad4134: Support buffered data read Marcelo Schmitt
2026-09-15 19:29   ` sashiko-bot
2026-09-21  1:50   ` Jonathan Cameron
2026-09-21 15:12     ` Marcelo Schmitt
2026-09-15 19:14 ` [PATCH v2 09/15] dt-bindings: iio: adc: adi,ad4134: Document SPI connection mode Marcelo Schmitt
2026-09-15 19:26   ` sashiko-bot
2026-09-15 21:57   ` Rob Herring (Arm)
2026-09-16 16:00   ` Rob Herring
2026-09-17  3:30     ` Jonathan Cameron
2026-09-17 16:07       ` Rob Herring
2026-09-17 16:54         ` Marcelo Schmitt
2026-09-15 19:15 ` [PATCH v2 10/15] dt-bindings: iio: adc: adi,ad4134: Document external multiplexer usage Marcelo Schmitt
2026-09-21  1:34   ` Jonathan Cameron
2026-09-15 19:15 ` [PATCH v2 11/15] iio: adc: ad4134: Support SPI 4-wire mode Marcelo Schmitt
2026-09-15 19:49   ` sashiko-bot
2026-09-21  1:50   ` Jonathan Cameron
2026-09-15 19:15 ` [PATCH v2 12/15] dt-bindings: iio: adc: adi,ad4134: Document PWM usage Marcelo Schmitt
2026-09-15 19:16 ` [PATCH v2 13/15] dt-bindings: iio: adc: adi,ad4134: Add high data throughput example Marcelo Schmitt
2026-09-15 19:28   ` sashiko-bot
2026-09-21  1:50   ` Jonathan Cameron
2026-09-24 21:25   ` Rob Herring
2026-09-15 19:16 ` [PATCH v2 14/15] iio: adc: ad4134: Support high-speed data capture Marcelo Schmitt
2026-09-15 19:50   ` sashiko-bot
2026-09-21  1:50   ` Jonathan Cameron
2026-09-15 19:16 ` [PATCH v2 15/15] Docs: iio: Add AD4134 Marcelo Schmitt

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915192811.B9CE21F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=marcelo.schmitt@analog.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.