From 2c605b45cc84a1c100e8a5e279949847d61647fb Mon Sep 17 00:00:00 2001 From: Jack Pham Date: Tue, 28 Jan 2020 20:14:42 -0800 Subject: [PATCH] usb: dwc3-msm: Fix out-of-bounds access in bus voting The for loop in dwc3_msm_update_bus_bw() was using a NULL condition rather than against ARRAY_SIZE(mdwc->icc_paths). This can result in an out-of-bounds access if the memory just beyond the array also happens to be non-zero. Change-Id: Ib1f003f774b125a156ceb0070cd9d98a4d1f03ee Signed-off-by: Jack Pham --- drivers/usb/dwc3/dwc3-msm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/dwc3/dwc3-msm.c b/drivers/usb/dwc3/dwc3-msm.c index 9db35699f77a..0fb09a98273a 100644 --- a/drivers/usb/dwc3/dwc3-msm.c +++ b/drivers/usb/dwc3/dwc3-msm.c @@ -2737,7 +2737,7 @@ static int dwc3_msm_update_bus_bw(struct dwc3_msm *mdwc, enum bus_vote bv) else if (bv == BUS_VOTE_NONE) bv_index = BUS_VOTE_NONE; - for (i = 0; mdwc->icc_paths[i]; i++) { + for (i = 0; i < ARRAY_SIZE(mdwc->icc_paths); i++) { ret = icc_set_bw(mdwc->icc_paths[i], bus_vote_values[bv_index][i].avg, bus_vote_values[bv_index][i].peak);