From ba4aef73619faa4c1f10aec0d467a2801e88d5b9 Mon Sep 17 00:00:00 2001 From: Raghavendra Rao Ananta Date: Tue, 12 May 2020 10:29:28 -0700 Subject: [PATCH] soc: qcom: socinfo: Fix array out-of-bounds access Socinfo driver's socinfo_get_id_string() does an array based indexing with the socid to get the entry for the current platform in soc_id[]. However, the soc_id[] is linearly mapped and not arranged to be indexed with the socid (unlike previous targets). This would cause an out-of-bounds array access in the soc_id[] array. Hence to fetch the name, rely on the already existing function, socinfo_machine(), which would iterate over the array and return a matching machine name for the id supplied. Change-Id: Ib7070732ac4ec99a32eb3f79c74abf2903398f53 Signed-off-by: Raghavendra Rao Ananta --- drivers/soc/qcom/socinfo.c | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/drivers/soc/qcom/socinfo.c b/drivers/soc/qcom/socinfo.c index 35b305ba6aca..2531302841d6 100644 --- a/drivers/soc/qcom/socinfo.c +++ b/drivers/soc/qcom/socinfo.c @@ -1163,20 +1163,6 @@ static void socinfo_print(void) } } -uint32_t socinfo_get_id(void) -{ - return (socinfo) ? le32_to_cpu(socinfo->id) : 0; -} -EXPORT_SYMBOL(socinfo_get_id); - -const char *socinfo_get_id_string(void) -{ - uint32_t id = socinfo_get_id(); - - return (socinfo) ? soc_id[id].name : NULL; -} -EXPORT_SYMBOL(socinfo_get_id_string); - static const char *socinfo_machine(unsigned int id) { int idx; @@ -1189,6 +1175,20 @@ static const char *socinfo_machine(unsigned int id) return NULL; } +uint32_t socinfo_get_id(void) +{ + return (socinfo) ? le32_to_cpu(socinfo->id) : 0; +} +EXPORT_SYMBOL(socinfo_get_id); + +const char *socinfo_get_id_string(void) +{ + uint32_t id = socinfo_get_id(); + + return socinfo_machine(id); +} +EXPORT_SYMBOL(socinfo_get_id_string); + static int qcom_socinfo_probe(struct platform_device *pdev) { struct qcom_socinfo *qs;