* [PATCH v3] iio: adc: stm32-adc: fix possible division by zero in processed channel
@ 2026-09-16 17:15 Fabrice Gasnier
2026-09-17 6:37 ` Andy Shevchenko
0 siblings, 1 reply; 3+ messages in thread
From: Fabrice Gasnier @ 2026-09-16 17:15 UTC (permalink / raw)
To: Jonathan Cameron, David Lechner, Nuno Sá, Andy Shevchenko,
Maxime Coquelin, Alexandre Torgue, Olivier Moysan,
Fabrice Gasnier
Cc: linux-iio, linux-stm32, linux-arm-kernel, linux-kernel,
Jonathan Cameron, Sashiko, stable
In case the conversion has failed or returned zero, processing *val
can lead to a division by zero. Need to check for errors, or converted
value is zero, before processing the data. In case the converted value
is zero, e.g. the Vrefint channel, this should be considered as invalid
in all cases.
Fixes: 0e346b2cfa85 ("iio: adc: stm32-adc: add vrefint calibration support")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260911161555.244F31F000FF@smtp.kernel.org/
Cc: stable@vger.kernel.org
Signed-off-by: Fabrice Gasnier <fabrice.gasnier@foss.st.com>
---
Changes in v3:
- New suggestion from Andy, to move lock release earlier, then return
when needed. Drop temporary variable.
- Link to v2: https://patch.msgid.link/20260916-adc-fix-div0-v2-1-f702d3ed782c@foss.st.com
Changes in v2:
- Review comments from Andy:
-- Correct commit message: single paragraph
-- Use a temporary variable instead of *val to improve readability
-- Drop ternary operation and use simpler conditional checks
- Link to v1: https://patch.msgid.link/20260915-adc-fix-div0-v1-1-7daed9e52f2f@foss.st.com
---
drivers/iio/adc/stm32-adc.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/iio/adc/stm32-adc.c b/drivers/iio/adc/stm32-adc.c
index 5c6c06b269be..cac9b18770a5 100644
--- a/drivers/iio/adc/stm32-adc.c
+++ b/drivers/iio/adc/stm32-adc.c
@@ -1608,11 +1608,16 @@ static int stm32_adc_read_raw(struct iio_dev *indio_dev,
ret = stm32_adc_single_conv(indio_dev, chan, val);
else
ret = -EINVAL;
+ iio_device_release_direct(indio_dev);
+ if (ret < 0)
+ return ret;
- if (mask == IIO_CHAN_INFO_PROCESSED)
+ if (mask == IIO_CHAN_INFO_PROCESSED) {
+ if (*val == 0)
+ return -EINVAL;
*val = STM32_ADC_VREFINT_VOLTAGE * adc->vrefint.vrefint_cal / *val;
+ }
- iio_device_release_direct(indio_dev);
return ret;
case IIO_CHAN_INFO_SCALE:
---
base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f
change-id: 20260915-adc-fix-div0-ae38365abfeb
Best regards,
--
Fabrice Gasnier <fabrice.gasnier@foss.st.com>
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH v3] iio: adc: stm32-adc: fix possible division by zero in processed channel
2026-09-16 17:15 [PATCH v3] iio: adc: stm32-adc: fix possible division by zero in processed channel Fabrice Gasnier
@ 2026-09-17 6:37 ` Andy Shevchenko
2026-09-21 0:15 ` Jonathan Cameron
0 siblings, 1 reply; 3+ messages in thread
From: Andy Shevchenko @ 2026-09-17 6:37 UTC (permalink / raw)
To: Fabrice Gasnier
Cc: Jonathan Cameron, David Lechner, Nuno Sá, Andy Shevchenko,
Maxime Coquelin, Alexandre Torgue, Olivier Moysan, linux-iio,
linux-stm32, linux-arm-kernel, linux-kernel, Sashiko, stable
On Wed, Sep 16, 2026 at 07:15:04PM +0200, Fabrice Gasnier wrote:
> In case the conversion has failed or returned zero, processing *val
> can lead to a division by zero. Need to check for errors, or converted
> value is zero, before processing the data. In case the converted value
> is zero, e.g. the Vrefint channel, this should be considered as invalid
> in all cases.
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
--
With Best Regards,
Andy Shevchenko
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v3] iio: adc: stm32-adc: fix possible division by zero in processed channel
2026-09-17 6:37 ` Andy Shevchenko
@ 2026-09-21 0:15 ` Jonathan Cameron
0 siblings, 0 replies; 3+ messages in thread
From: Jonathan Cameron @ 2026-09-21 0:15 UTC (permalink / raw)
To: Andy Shevchenko
Cc: Fabrice Gasnier, David Lechner, Nuno Sá, Andy Shevchenko,
Maxime Coquelin, Alexandre Torgue, Olivier Moysan, linux-iio,
linux-stm32, linux-arm-kernel, linux-kernel, Sashiko, stable
On Thu, 17 Sep 2026 09:37:27 +0300
Andy Shevchenko <andriy.shevchenko@intel.com> wrote:
> On Wed, Sep 16, 2026 at 07:15:04PM +0200, Fabrice Gasnier wrote:
> > In case the conversion has failed or returned zero, processing *val
> > can lead to a division by zero. Need to check for errors, or converted
> > value is zero, before processing the data. In case the converted value
> > is zero, e.g. the Vrefint channel, this should be considered as invalid
> > in all cases.
>
> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
>
Applied to the fixes-togreg branch of iio.git.
Note this may well not go upstream until next merge window.
Thanks,
Jonathan
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-21 0:16 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 17:15 [PATCH v3] iio: adc: stm32-adc: fix possible division by zero in processed channel Fabrice Gasnier
2026-09-17 6:37 ` Andy Shevchenko
2026-09-21 0:15 ` Jonathan Cameron
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox