All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] hwmon: (pmbus) Validate number of phases per page
@ 2026-09-12 14:50 Guenter Roeck
  2026-09-12 15:07 ` sashiko-bot
  2026-09-14 12:21 ` Nuno Sá
  0 siblings, 2 replies; 3+ messages in thread
From: Guenter Roeck @ 2026-09-12 14:50 UTC (permalink / raw)
  To: Hardware Monitoring; +Cc: Guenter Roeck, Nuno Sá

It is possible for a PMBus driver to configure a phase count larger than
the PMBUS_PHASES limit and cause an out-of-bounds read.

Add a bounds check for info->phases against PMBUS_PHASES in the core API
to prevent the potential out-of-bounds read.

Cc: Nuno Sá <nuno.sa@analog.com>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
---
 drivers/hwmon/pmbus/pmbus_core.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/hwmon/pmbus/pmbus_core.c b/drivers/hwmon/pmbus/pmbus_core.c
index 5104fd29307b..d69f1bde1795 100644
--- a/drivers/hwmon/pmbus/pmbus_core.c
+++ b/drivers/hwmon/pmbus/pmbus_core.c
@@ -2982,6 +2982,11 @@ static int pmbus_init_common(struct i2c_client *client, struct pmbus_data *data,
 	}
 
 	for (page = 0; page < info->pages; page++) {
+		if (info->phases[page] > PMBUS_PHASES) {
+			dev_err(dev, "Bad number of PMBus phases for page %d: %d\n",
+				page, info->phases[page]);
+			return -ENODEV;
+		}
 		ret = pmbus_identify_common(client, data, page);
 		if (ret < 0) {
 			dev_err(dev, "Failed to identify chip capabilities\n");
-- 
2.45.2


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-14 12:20 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-12 14:50 [PATCH] hwmon: (pmbus) Validate number of phases per page Guenter Roeck
2026-09-12 15:07 ` sashiko-bot
2026-09-14 12:21 ` Nuno Sá

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.