staging: iio: frequency: ad9834: Validate frequency parameter value
authorAleksandr Mishin <amishin@t-argos.ru>
Wed, 3 Jul 2024 15:45:06 +0000 (18:45 +0300)
committerJonathan Cameron <Jonathan.Cameron@huawei.com>
Mon, 29 Jul 2024 19:31:23 +0000 (20:31 +0100)
In ad9834_write_frequency() clk_get_rate() can return 0. In such case
ad9834_calc_freqreg() call will lead to division by zero. Checking
'if (fout > (clk_freq / 2))' doesn't protect in case of 'fout' is 0.
ad9834_write_frequency() is called from ad9834_write(), where fout is
taken from text buffer, which can contain any value.

Modify parameters checking.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 12b9d5bf76bf ("Staging: IIO: DDS: AD9833 / AD9834 driver")
Suggested-by: Dan Carpenter <dan.carpenter@linaro.org>
Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
Reviewed-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://patch.msgid.link/20240703154506.25584-1-amishin@t-argos.ru
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
drivers/staging/iio/frequency/ad9834.c

index a7a5cdcc65903a77a2175710452c9f6dbee1b0ca..47e7d7e6d92089e88acdfd45926f785425565e4d 100644 (file)
@@ -114,7 +114,7 @@ static int ad9834_write_frequency(struct ad9834_state *st,
 
        clk_freq = clk_get_rate(st->mclk);
 
-       if (fout > (clk_freq / 2))
+       if (!clk_freq || fout > (clk_freq / 2))
                return -EINVAL;
 
        regval = ad9834_calc_freqreg(clk_freq, fout);