From patchwork Fri Feb 23 13:38:35 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Geert Uytterhoeven X-Patchwork-Id: 877095 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=lists.infradead.org (client-ip=2607:7c80:54:e::133; helo=bombadil.infradead.org; envelope-from=linux-snps-arc-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org; receiver=) Authentication-Results: ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="sGlklzsR"; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=infradead.org header.i=@infradead.org header.b="CGtP9h4X"; dkim-atps=neutral Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:e::133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3znt9R2FbQz9sW7 for ; Sat, 24 Feb 2018 00:58:35 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:MIME-Version:Cc:List-Subscribe: List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:References: In-Reply-To:Message-Id:Date:Subject:To:From:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Owner; bh=A2UC+SM6Nplz30qhRo7K8ZO7R57OWUa1muUopBisx/Y=; b=sGlklzsRTT3SovZ+jsTin4v3zC Au9NW4AEScXzqy93GAGcj4b6Gp9AEh4rfRSCneitIUOfXoeTeQ00o+ieUsIUWiu9GehYMyAWzjmw+ 99VBjjXxNa2pnYsgD7Neu1gkSFth31OvOGQefaieJU5RqQ6WhqUyWwl6UHMgDk+SPfVWxWFylsZpd KmJZxg7lmHTYt4zHRlTyMUEWxWijrNwwJ1x/togMpMYyfUVhI+d7j5KsuWEWYCAwrNDFl9lukvOXU 0737pJk+FhOe1CdfwyouUcfy5zLGIR8HEj1hJHCeHSeAy3uZwQeecYUQJvFOV9cPdprzL5xQRFWX4 DM2TFMFQ==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.89 #1 (Red Hat Linux)) id 1epDrr-0006zq-QE; Fri, 23 Feb 2018 13:58:31 +0000 Received: from casper.infradead.org ([85.118.1.10]) by bombadil.infradead.org with esmtps (Exim 4.89 #1 (Red Hat Linux)) id 1epDnz-0003LI-GD for linux-snps-arc@bombadil.infradead.org; Fri, 23 Feb 2018 13:54:31 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=infradead.org; s=casper.20170209; h=References:In-Reply-To:Message-Id:Date: Subject:Cc:To:From:Sender:Reply-To:MIME-Version:Content-Type: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=RR4UMlFXwC9+7UdYRdDWais3pNW4unjiOtKUyETeGs4=; b=CGtP9h4XxDC+CEXHKf8g2YoFm mXbX1Ux6SqGxNOz7A+74W2JYsDQ5BD765xS/ydYjOw7WPTkH+XgxYVwMqT2hFnUN1isO5dWFaTY8S 0icBK/hR69uKMaJjmtW0TdUmGkWiJTmmq8J8dIyJ6GmFH4RbtgRBnWN+L87jJPa9oa6MBbSfuenb5 TEkdyVXC5J2SwOuyljbNZckcUVRpej9f0+UeRrgjuuUs2QRQVr/vZgcPBIMzI29J7hdzGlYl3otdp N1spQoH9qEIedpT2vplzMqUeycP1Fn15t+mKjokwrv1A08OcTj1sm0wrc5LbVAGNeFVY5ErikIhHh HEUIFeAWw==; Received: from leibniz.telenet-ops.be ([195.130.137.77]) by casper.infradead.org with esmtps (Exim 4.89 #1 (Red Hat Linux)) id 1epDYv-0003Xt-8o for linux-snps-arc@lists.infradead.org; Fri, 23 Feb 2018 13:39:00 +0000 Received: from michel.telenet-ops.be (michel.telenet-ops.be [IPv6:2a02:1800:110:4::f00:18]) by leibniz.telenet-ops.be (Postfix) with ESMTPS id 3znskY45VXzMqn4Y for ; Fri, 23 Feb 2018 14:38:45 +0100 (CET) Received: from ayla.of.borg ([84.194.111.163]) by michel.telenet-ops.be with bizsmtp id EDee1x00r3XaVaC06DeehX; Fri, 23 Feb 2018 14:38:41 +0100 Received: from ramsan.of.borg ([192.168.97.29] helo=ramsan) by ayla.of.borg with esmtp (Exim 4.86_2) (envelope-from ) id 1epDYc-0004su-Q0; Fri, 23 Feb 2018 14:38:38 +0100 Received: from geert by ramsan with local (Exim 4.86_2) (envelope-from ) id 1epDYc-0008Lq-OV; Fri, 23 Feb 2018 14:38:38 +0100 From: Geert Uytterhoeven To: Greg Kroah-Hartman Subject: [PATCH v2 7/9] serial: sh-sci: Fix out-of-bounds access through DT alias Date: Fri, 23 Feb 2018 14:38:35 +0100 Message-Id: <1519393117-31998-8-git-send-email-geert+renesas@glider.be> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1519393117-31998-1-git-send-email-geert+renesas@glider.be> References: <1519393117-31998-1-git-send-email-geert+renesas@glider.be> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20180223_133857_339061_5CA93A53 X-CRM114-Status: UNSURE ( 8.31 ) X-CRM114-Notice: Please train this message. X-Spam-Score: -2.4 (--) X-Spam-Report: SpamAssassin version 3.4.1 on casper.infradead.org summary: Content analysis details: (-2.4 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [195.130.137.77 listed in list.dnswl.org] 0.2 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail domains are different -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] X-BeenThere: linux-snps-arc@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: Linux on Synopsys ARC Processors List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: devicetree@vger.kernel.org, Barry Song , Geert Uytterhoeven , Vineet Gupta , Michal Simek , linux-kernel@vger.kernel.org, linux-renesas-soc@vger.kernel.org, linux-serial@vger.kernel.org, Jiri Slaby , linux-snps-arc@lists.infradead.org, linux-arm-kernel@lists.infradead.org MIME-Version: 1.0 Sender: "linux-snps-arc" Errors-To: linux-snps-arc-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org The sci_ports[] array is indexed using a value derived from the "serialN" alias in DT, which may lead to an out-of-bounds access. Fix this by adding a range check. Note that the array size is defined by a Kconfig symbol (CONFIG_SERIAL_SH_SCI_NR_UARTS), so this can even be triggered using a legitimate DTB. Fixes: 97ed9790c514066b ("serial: sh-sci: Remove unused platform data capabilities field") Signed-off-by: Geert Uytterhoeven --- v2: - Fix Fixes reference, - Use ARRAY_SIZE(). --- drivers/tty/serial/sh-sci.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/tty/serial/sh-sci.c b/drivers/tty/serial/sh-sci.c index 4d14f321cbec95e0..f6a6610d434efc33 100644 --- a/drivers/tty/serial/sh-sci.c +++ b/drivers/tty/serial/sh-sci.c @@ -3096,6 +3096,10 @@ static struct plat_sci_port *sci_parse_dt(struct platform_device *pdev, dev_err(&pdev->dev, "failed to get alias id (%d)\n", id); return NULL; } + if (id >= ARRAY_SIZE(sci_ports)) { + dev_err(&pdev->dev, "serial%d out of range\n", id); + return NULL; + } sp = &sci_ports[id]; *dev_id = id;