intel_scu_ipcutil: underflow in scu_reg_access()
"count" is controlled by the user and it can be negative. Let's prevent
that by making it unsigned. You have to have CAP_SYS_RAWIO to call this
function so the bug is not as serious as it could be.
Fixes: 5369c02d95
('intel_scu_ipc: Utility driver for intel scu ipc')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Cc: stable@vger.kernel.org
Signed-off-by: Darren Hart <dvhart@linux.intel.com>
This commit is contained in:
parent
1c319e781e
commit
b1d353ad3d
@ -49,7 +49,7 @@ struct scu_ipc_data {
|
|||||||
|
|
||||||
static int scu_reg_access(u32 cmd, struct scu_ipc_data *data)
|
static int scu_reg_access(u32 cmd, struct scu_ipc_data *data)
|
||||||
{
|
{
|
||||||
int count = data->count;
|
unsigned int count = data->count;
|
||||||
|
|
||||||
if (count == 0 || count == 3 || count > 4)
|
if (count == 0 || count == 3 || count > 4)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
Loading…
Reference in New Issue
Block a user