diff options
| author | Babanpreet Singh <bbnpreetsingh@gmail.com> | 2026-07-18 18:22:36 +0000 |
|---|---|---|
| committer | Jonathan Cameron <jonathan.cameron@oss.qualcomm.com> | 2026-08-07 23:51:03 +0100 |
| commit | f2c5c76306fadb834dd5ea76cab0b7cd447e6035 (patch) | |
| tree | bfbcf1d9179a7b5683447abf59d88c1686ca0c44 /tools/perf/scripts/python/bin/stackcollapse-record | |
| parent | 739aac87638f06fcf851df41ecd52d30ab7b0570 (diff) | |
iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show
ad3552r_hs_show_data_source_avail() formats the available data source
names into a 128-byte stack buffer, but bounds each scnprintf() with
PAGE_SIZE instead of the buffer size, so the bound does not protect
the destination at all.
This cannot overflow today - dbgfs_attr_source[] has two entries,
"normal" and "ramp-16bit", 18 bytes formatted - but the bound stops
protecting the stack the day the table grows. Use sizeof(buf) so the
bound matches the destination.
Found by smatch:
drivers/iio/dac/ad3552r-hs.c:593 ad3552r_hs_show_data_source_avail()
error: scnprintf() 'buf[len]' too small (128 vs 4096)
Fixes: b1c5d68ea66e ("iio: dac: ad3552r-hs: add support for internal ramp")
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Diffstat (limited to 'tools/perf/scripts/python/bin/stackcollapse-record')
0 files changed, 0 insertions, 0 deletions
