]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
mtd: cfi: use struct_size() helper for cfiq allocation
authorGopi Krishna Menon <krishnagopi487@gmail.com>
Thu, 18 Sep 2025 18:44:14 +0000 (00:14 +0530)
committerMiquel Raynal <miquel.raynal@bootlin.com>
Mon, 29 Sep 2025 16:01:32 +0000 (18:01 +0200)
Documentation/process/deprecated.rst recommends against performing
dynamic size calculations in the arguments of memory allocator
function due to the risk of overflow. Such calculations can
wrap around and result in a smaller allocation than what the caller
was expecting.

Replace the size calculation in cfiq allocation with struct_size()
helper to make the code clearer and handle the overflows correctly.

Signed-off-by: Gopi Krishna Menon <krishnagopi487@gmail.com>
Reviewed-by: Vignesh Raghavendra <vigneshr@ti.com>
link: https://lore.kernel.org/linux-kernel-mentees/20250922071137.900508-1-rk0006818@gmail.com/T/#u
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
drivers/mtd/chips/cfi_probe.c

index a04b6174181c4579b803744868fc6a14f5f704d3..e254f9cd27968a50677312ba92952a2d8df6c7c3 100644 (file)
@@ -208,7 +208,7 @@ static int __xipram cfi_chip_setup(struct map_info *map,
        if (!num_erase_regions)
                return 0;
 
-       cfi->cfiq = kmalloc(sizeof(struct cfi_ident) + num_erase_regions * 4, GFP_KERNEL);
+       cfi->cfiq = kmalloc(struct_size(cfi->cfiq, EraseRegionInfo, num_erase_regions), GFP_KERNEL);
        if (!cfi->cfiq)
                return 0;