Skip to content

hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field

Steve Best requested to merge sfbest/centos-stream-9:37721 into main

JIRA: https://issues.redhat.com/browse/RHEL-37721
CVE: CVE-2021-47385

Build Info: https://brewweb.engineering.redhat.com/brew/taskinfo?taskID=61470814
Tested: Did sanity boot testing Intel (intel-arrowlake-s-02) system.

commit 0f36b88173f028e372668ae040ab1a496834d278
Author: Nadezda Lutovinova lutovinova@ispras.ru
Date: Tue Sep 21 18:51:52 2021 +0300

hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field  

If driver read val value sufficient for  
(val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7))  
from device then Null pointer dereference occurs.  
(It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers)  
Also lm75[] does not serve a purpose anymore after switching to  
devm_i2c_new_dummy_device() in w83791d_detect_subclients().  

The patch fixes possible NULL pointer dereference by removing lm75[].  

Found by Linux Driver Verification project (linuxtesting.org).  

Cc: stable@vger.kernel.org  
Signed-off-by: Nadezda Lutovinova <lutovinova@ispras.ru>  
Link: https://lore.kernel.org/r/20210921155153.28098-2-lutovinova@ispras.ru  
[groeck: Dropped unnecessary continuation lines, fixed multipline alignment]  
Signed-off-by: Guenter Roeck <linux@roeck-us.net>  

Signed-off-by: Steve Best sbest@redhat.com

Merge request reports

Loading