From: Fabrice Gasnier <fabrice.gasnier@foss.st.com>
To: "Jonathan Cameron" <jic23@kernel.org>,
"David Lechner" <dlechner@baylibre.com>,
"Nuno Sá" <nuno.sa@analog.com>,
"Andy Shevchenko" <andy@kernel.org>,
"Maxime Coquelin" <mcoquelin.stm32@gmail.com>,
"Alexandre Torgue" <alexandre.torgue@foss.st.com>,
"Olivier Moysan" <olivier.moysan@foss.st.com>,
"Fabrice Gasnier" <fabrice.gasnier@foss.st.com>
Cc: <linux-iio@vger.kernel.org>,
<linux-stm32@st-md-mailman.stormreply.com>,
<linux-arm-kernel@lists.infradead.org>,
<linux-kernel@vger.kernel.org>,
Jonathan Cameron <jic23@kernel.org>,
Sashiko <sashiko-bot@kernel.org>, <stable@vger.kernel.org>
Subject: [PATCH v3] iio: adc: stm32-adc: fix possible division by zero in processed channel
Date: Wed, 16 Sep 2026 19:15:04 +0200 [thread overview]
Message-ID: <20260916-adc-fix-div0-v3-1-bedf027a6e7e@foss.st.com> (raw)
In case the conversion has failed or returned zero, processing *val
can lead to a division by zero. Need to check for errors, or converted
value is zero, before processing the data. In case the converted value
is zero, e.g. the Vrefint channel, this should be considered as invalid
in all cases.
Fixes: 0e346b2cfa85 ("iio: adc: stm32-adc: add vrefint calibration support")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260911161555.244F31F000FF@smtp.kernel.org/
Cc: stable@vger.kernel.org
Signed-off-by: Fabrice Gasnier <fabrice.gasnier@foss.st.com>
---
Changes in v3:
- New suggestion from Andy, to move lock release earlier, then return
when needed. Drop temporary variable.
- Link to v2: https://patch.msgid.link/20260916-adc-fix-div0-v2-1-f702d3ed782c@foss.st.com
Changes in v2:
- Review comments from Andy:
-- Correct commit message: single paragraph
-- Use a temporary variable instead of *val to improve readability
-- Drop ternary operation and use simpler conditional checks
- Link to v1: https://patch.msgid.link/20260915-adc-fix-div0-v1-1-7daed9e52f2f@foss.st.com
---
drivers/iio/adc/stm32-adc.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/iio/adc/stm32-adc.c b/drivers/iio/adc/stm32-adc.c
index 5c6c06b269be..cac9b18770a5 100644
--- a/drivers/iio/adc/stm32-adc.c
+++ b/drivers/iio/adc/stm32-adc.c
@@ -1608,11 +1608,16 @@ static int stm32_adc_read_raw(struct iio_dev *indio_dev,
ret = stm32_adc_single_conv(indio_dev, chan, val);
else
ret = -EINVAL;
+ iio_device_release_direct(indio_dev);
+ if (ret < 0)
+ return ret;
- if (mask == IIO_CHAN_INFO_PROCESSED)
+ if (mask == IIO_CHAN_INFO_PROCESSED) {
+ if (*val == 0)
+ return -EINVAL;
*val = STM32_ADC_VREFINT_VOLTAGE * adc->vrefint.vrefint_cal / *val;
+ }
- iio_device_release_direct(indio_dev);
return ret;
case IIO_CHAN_INFO_SCALE:
---
base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f
change-id: 20260915-adc-fix-div0-ae38365abfeb
Best regards,
--
Fabrice Gasnier <fabrice.gasnier@foss.st.com>
next reply other threads:[~2026-09-16 17:16 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 17:15 Fabrice Gasnier [this message]
2026-09-17 6:37 ` [PATCH v3] iio: adc: stm32-adc: fix possible division by zero in processed channel Andy Shevchenko
2026-09-21 0:15 ` Jonathan Cameron
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916-adc-fix-div0-v3-1-bedf027a6e7e@foss.st.com \
--to=fabrice.gasnier@foss.st.com \
--cc=alexandre.torgue@foss.st.com \
--cc=andy@kernel.org \
--cc=dlechner@baylibre.com \
--cc=jic23@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-iio@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-stm32@st-md-mailman.stormreply.com \
--cc=mcoquelin.stm32@gmail.com \
--cc=nuno.sa@analog.com \
--cc=olivier.moysan@foss.st.com \
--cc=sashiko-bot@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox