All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Javier Carrasco" <javier.carrasco.cruz@gmail.com>
To: "Karan Sanghavi" <karansanghvi98@gmail.com>,
	"Jonathan Cameron" <jic23@kernel.org>,
	"Lars-Peter Clausen" <lars@metafoo.de>
Cc: "Jonathan Cameron" <Jonathan.Cameron@huawei.com>,
	<linux-iio@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
	"Shuah Khan" <skhan@linuxfoundation.org>
Subject: Re: [PATCH] iio: light: Add check for array bounds in veml6075_read_int_time_ms
Date: Sun, 02 Feb 2025 18:09:45 +0100	[thread overview]
Message-ID: <D7I4JY638HIU.1OH0ECMRKC7K7@gmail.com> (raw)
In-Reply-To: <20250202-outofboundsread1573409-v1-1-5e3dd97a24a6@gmail.com>

On Sun Feb 2, 2025 at 11:49 AM CET, Karan Sanghavi wrote:
> The array contains only 5 elements, but the index calculated by
> veml6075_read_int_time_index can range from 0 to 7,
> which could lead to out-of-bounds access. The check prevents this issue.
>
> Coverity Issue
> CID 1574309: (#1 of 1): Out-of-bounds read (OVERRUN)
> overrun-local: Overrunning array veml6075_it_ms of 5 4-byte
> elements at element index 7 (byte offset 31) using
> index int_index (which evaluates to 7)
>
> Fixes: 3b82f43238ae ("iio: light: add VEML6075 UVA and UVB light sensor driver")
> Signed-off-by: Karan Sanghavi <karansanghvi98@gmail.com>
> ---
>  drivers/iio/light/veml6075.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/iio/light/veml6075.c b/drivers/iio/light/veml6075.c
> index 05d4c0e9015d..a892330582f4 100644
> --- a/drivers/iio/light/veml6075.c
> +++ b/drivers/iio/light/veml6075.c
> @@ -210,7 +210,7 @@ static int veml6075_read_int_time_ms(struct veml6075_data *data, int *val)
>
>  	guard(mutex)(&data->lock);
>  	int_index = veml6075_read_int_time_index(data);
> -	if (int_index < 0)
> +	if (int_index < 0 || int_index >= ARRAY_SIZE(veml6075_it_ms))
>  		return int_index;
>
>  	*val = veml6075_it_ms[int_index];
>
> ---
> base-commit: df4b2bbff898227db0c14264ac7edd634e79f755
> change-id: 20250202-outofboundsread1573409-378997439be1
>
> Best regards,


Hi Karan,

Thanks for your patch. That could never happen because the device does
not support those values: it only delivers values between 0 and 4 for
that field because it does not support more integration times.

Even though the check does not do anything in reality, it does not hurt
either, and I would like to avoid future noise from coverity.

Reviewed-by: Javier Carrasco <javier.carrasco.cruz@gmail.com>

  reply	other threads:[~2025-02-02 17:09 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-02-02 10:49 [PATCH] iio: light: Add check for array bounds in veml6075_read_int_time_ms Karan Sanghavi
2025-02-02 17:09 ` Javier Carrasco [this message]
2025-02-03  5:14   ` Javier Carrasco

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=D7I4JY638HIU.1OH0ECMRKC7K7@gmail.com \
    --to=javier.carrasco.cruz@gmail.com \
    --cc=Jonathan.Cameron@huawei.com \
    --cc=jic23@kernel.org \
    --cc=karansanghvi98@gmail.com \
    --cc=lars@metafoo.de \
    --cc=linux-iio@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=skhan@linuxfoundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.