diff options
| author | Guenter Roeck <linux@roeck-us.net> | 2026-08-04 16:26:05 -0700 |
|---|---|---|
| committer | Guenter Roeck <linux@roeck-us.net> | 2026-08-06 22:37:44 -0700 |
| commit | e253dd5f9f6d875a317895bf43ec9534ed7523cb (patch) | |
| tree | 5d09cbf0a572bcbe4a7cb456109b9421684b4ace /tools/perf/scripts/python/task-analyzer.py | |
| parent | edd11a94335747423569500a194c6eaa915f2963 (diff) | |
hwmon: (ltc4282) Clamp negative current limits
When a negative value is passed to ltc4282_write_curr(), the signed long
val is cast directly to u64:
drivers/hwmon/ltc4282.c:ltc4282_write_curr() {
/* need to pass it in millivolt */
u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);
...
}
This cast converts negative inputs into large positive values. The
subsequent division result overflows the u32 in variable, truncating
to a pseudo-random positive value. When this is passed to
ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead
of zero.
Clamp val to 0 and to the maximum supported upper limit before the cast
and assign the result to a 64-bit temporary variable before the division
to avoid the underflow and an also possible overflow.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: cbc29538dbf7d ("hwmon: Add driver for LTC4282")
Cc: Nuno Sa <nuno.sa@analog.com>
Reviewed-by: Nuno Sá <nuno.sa@analog.com>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Diffstat (limited to 'tools/perf/scripts/python/task-analyzer.py')
0 files changed, 0 insertions, 0 deletions
