The boundary checks in airoha_clk_enable(), airoha_clk_get_rate(), and
airoha_clk_set_rate() use "id > data->num_clocks" which allows id equal
to num_clocks to pass. Since data->descs[] has exactly num_clocks entries
(indices 0 to num_clocks-1), id=num_clocks results in an out-of-bounds
array access.
This is currently not triggered because the device tree clock IDs are
within bounds, but the check should be defensive. Fix by changing the
comparison from ">" to ">=".
Fixes: d0b81afb5ec9 ("clk: airoha: Add support for Airoha AN7581 SoC clock")
Signed-off-by: Wayen Yan <win847@gmail.com>
struct airoha_clk_soc_data *data = priv->data;
int id = clk->id;
- if (id > data->num_clocks)
+ if (id >= data->num_clocks)
return -EINVAL;
return 0;
ulong rate;
int ret;
- if (id > data->num_clocks) {
+ if (id >= data->num_clocks) {
dev_err(clk->dev, "Invalid clk ID %d\n", id);
return 0;
}
int div;
int ret;
- if (id > data->num_clocks) {
+ if (id >= data->num_clocks) {
dev_err(clk->dev, "Invalid clk ID %d\n", id);
return 0;
}