]> git.ipfire.org Git - thirdparty/u-boot.git/commit
clk: airoha: fix off-by-one in clock ID boundary check
authorWayen Yan <win847@gmail.com>
Wed, 8 Jul 2026 04:06:08 +0000 (12:06 +0800)
committerTom Rini <trini@konsulko.com>
Fri, 17 Jul 2026 20:50:35 +0000 (14:50 -0600)
commitfdfe2ec48d5c1c2ed03073d73edd3fdd3fe1ffa1
tree76dbb4269a67e3e329cebf1c38a7db1161b680ce
parenta1a944f25c10dfa2ae3b344acbbeac39dc929bb8
clk: airoha: fix off-by-one in clock ID boundary check

The boundary checks in airoha_clk_enable(), airoha_clk_get_rate(), and
airoha_clk_set_rate() use "id > data->num_clocks" which allows id equal
to num_clocks to pass. Since data->descs[] has exactly num_clocks entries
(indices 0 to num_clocks-1), id=num_clocks results in an out-of-bounds
array access.

This is currently not triggered because the device tree clock IDs are
within bounds, but the check should be defensive. Fix by changing the
comparison from ">" to ">=".

Fixes: d0b81afb5ec9 ("clk: airoha: Add support for Airoha AN7581 SoC clock")
Signed-off-by: Wayen Yan <win847@gmail.com>
drivers/clk/airoha/clk-airoha.c