summaryrefslogtreecommitdiffstats
path: root/drivers/usb/gadget/udc
diff options
context:
space:
mode:
authorMa Ke <make24@iscas.ac.cn>2024-06-25 04:23:06 +0200
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2024-06-27 16:07:30 +0200
commitee0d382feb44ec0f445e2ad63786cd7f3f6a8199 (patch)
treed78d0324d88a00741df1b8fcc6578ff3412d9f1c /drivers/usb/gadget/udc
parentusb: chipidea: ci_hdrc_tegra: Switch to RUNTIME_PM_OPS() (diff)
downloadlinux-ee0d382feb44ec0f445e2ad63786cd7f3f6a8199.tar.xz
linux-ee0d382feb44ec0f445e2ad63786cd7f3f6a8199.zip
usb: gadget: aspeed_udc: validate endpoint index for ast udc
We should verify the bound of the array to assure that host may not manipulate the index to point past endpoint array. Found by static analysis. Signed-off-by: Ma Ke <make24@iscas.ac.cn> Reviewed-by: Andrew Jeffery <andrew@codeconstruct.com.au> Acked-by: Andrew Jeffery <andrew@codeconstruct.com.au> Link: https://lore.kernel.org/r/20240625022306.2568122-1-make24@iscas.ac.cn Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/usb/gadget/udc')
-rw-r--r--drivers/usb/gadget/udc/aspeed_udc.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/drivers/usb/gadget/udc/aspeed_udc.c b/drivers/usb/gadget/udc/aspeed_udc.c
index 3916c8e2ba01..d972ef4644bc 100644
--- a/drivers/usb/gadget/udc/aspeed_udc.c
+++ b/drivers/usb/gadget/udc/aspeed_udc.c
@@ -1009,6 +1009,8 @@ static void ast_udc_getstatus(struct ast_udc_dev *udc)
break;
case USB_RECIP_ENDPOINT:
epnum = crq.wIndex & USB_ENDPOINT_NUMBER_MASK;
+ if (epnum >= AST_UDC_NUM_ENDPOINTS)
+ goto stall;
status = udc->ep[epnum].stopped;
break;
default: