Skip to content

Commit 82f2aab

Browse files
jtstrsgroeck
authored andcommitted
hwmon: (tmp401) fix overflow caused by default conversion rate value
The driver computes conversion intervals using the formula: interval = (1 << (7 - rate)) * 125ms where 'rate' is the sensor's conversion rate register value. According to the datasheet, the power-on reset value of this register is 0x8, which could be assigned to the register, after handling i2c general call. Using this default value causes a result greater than the bit width of left operand and an undefined behaviour in the calculation above, since shifting by values larger than the bit width is undefined behaviour as per C language standard. Limit the maximum usable 'rate' value to 7 to prevent undefined behaviour in calculations. Found by Linux Verification Center (linuxtesting.org) with Svace. Note (groeck): This does not matter in practice unless someone overwrites the chip configuration from outside the driver while the driver is loaded. The conversion time register is initialized with a value of 5 (500ms) when the driver is loaded, and the driver never writes a bad value. Fixes: ca53e76 ("hwmon: (tmp401) Convert to _info API") Signed-off-by: Alexey Simakov <bigalex934@gmail.com> Link: https://lore.kernel.org/r/20251211164342.6291-1-bigalex934@gmail.com Signed-off-by: Guenter Roeck <linux@roeck-us.net>
1 parent 6946c72 commit 82f2aab

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

drivers/hwmon/tmp401.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -397,7 +397,7 @@ static int tmp401_chip_read(struct device *dev, u32 attr, int channel, long *val
397397
ret = regmap_read(data->regmap, TMP401_CONVERSION_RATE, &regval);
398398
if (ret < 0)
399399
return ret;
400-
*val = (1 << (7 - regval)) * 125;
400+
*val = (1 << (7 - min(regval, 7))) * 125;
401401
break;
402402
case hwmon_chip_temp_reset_history:
403403
*val = 0;

0 commit comments

Comments
 (0)