Charge:fix slab out of bounds risk

There is a risk if enum mmi_temp_zones value > num_temp_zones.
This will casue pointer point to a illegal memory address.

Change-Id: Ib34f471d55e7b68e8cf11ec07ede19fbf5f22815
Signed-off-by: chailu1 <chailu1@lenovo.com>
Reviewed-on: https://gerrit.mot.com/1456934
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Haijian Ma <mahj8@motorola.com>
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Submit-Approved: Jira Key
This commit is contained in:
chailu1 2019-11-18 16:46:09 +08:00 • committed by Lu Chai
commit 2c3d417c78

View file

@ -2550,7 +2550,10 @@ static void mmi_basic_charge_sm(struct smb_mmi_charger *chip,
max_fv_mv = chip->base_fv_mv;
mmi_find_temp_zone(chip, prm, stat->batt_temp);
zone = &prm->temp_zones[prm->pres_temp_zone];
if (prm->pres_temp_zone >= prm->num_temp_zones)
zone = &prm->temp_zones[0];
else
zone = &prm->temp_zones[prm->pres_temp_zone];
if (!stat->charger_present && !is_wls_online(chip)) {
prm->pres_chrg_step = STEP_NONE;