diff options
author | Axel Lin <axel.lin@gmail.com> | 2011-05-16 14:19:01 (GMT) |
---|---|---|
committer | Liam Girdwood <lrg@slimlogic.co.uk> | 2011-05-27 09:49:09 (GMT) |
commit | 0514e9acd7655c708fbf12a659ea43d835bc688a (patch) | |
tree | 5f9ecf1224773a0ca671d8d516c507d133cbf2f1 /lib/random32.c | |
parent | 4aa922c024b2a194d7b68b22a66dfcf86e7838b3 (diff) | |
download | linux-fsl-qoriq-0514e9acd7655c708fbf12a659ea43d835bc688a.tar.xz |
mfd: Fix off-by-one value range checking for tps65910_i2c_write
If bytes == (TPS65910_MAX_REGISTER + 1), we have a buffer overflow when
doing memcpy(&msg[1], src, bytes).
Signed-off-by: Axel Lin <axel.lin@gmail.com>
Acked-by: Samuel Ortiz <sameo@linux.intel.com>
Signed-off-by: Liam Girdwood <lrg@slimlogic.co.uk>
Diffstat (limited to 'lib/random32.c')
0 files changed, 0 insertions, 0 deletions