mei: bus: type promotion bug in mei_nfc_if_version()
authorDan Carpenter <dan.carpenter@oracle.com>
Wed, 11 Jul 2018 12:29:31 +0000 (15:29 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 12 Jul 2018 13:44:57 +0000 (15:44 +0200)
We accidentally removed the check for negative returns
without considering the issue of type promotion.
The "if_version_length" variable is type size_t so if __mei_cl_recv()
returns a negative then "bytes_recv" is type promoted
to a high positive value and treated as success.

Cc: <stable@vger.kernel.org>
Fixes: 582ab27a063a ("mei: bus: fix received data size check in NFC fixup")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/misc/mei/bus-fixup.c

index e45fe826d87d3e68372152ff2173a77501388f6d..65e28be3c8cc4d224ff892cf82ba8a30d649094b 100644 (file)
@@ -341,7 +341,7 @@ static int mei_nfc_if_version(struct mei_cl *cl,
 
        ret = 0;
        bytes_recv = __mei_cl_recv(cl, (u8 *)reply, if_version_length, 0, 0);
-       if (bytes_recv < if_version_length) {
+       if (bytes_recv < 0 || bytes_recv < if_version_length) {
                dev_err(bus->dev, "Could not read IF version\n");
                ret = -EIO;
                goto err;