On Sun Jul 19 13:08:35 2026 +0000, Ilya Krutskih wrote:
> Integer overflow may occur, when variable exp equals to zero. Result
> of shift 1 << (exp - 1) may then leads to undefined behavior.
> 
> Fixes: 148abd3b5b14 ("media: tda18250: support for new silicon tuner")
> Cc: [email protected]
> Signed-off-by: Ilya Krutskih <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/tuners/tda18250.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/tuners/tda18250.c b/drivers/media/tuners/tda18250.c
index 7bb945ba0989..bd7ed50fb6e8 100644
--- a/drivers/media/tuners/tda18250.c
+++ b/drivers/media/tuners/tda18250.c
@@ -440,8 +440,8 @@ static int tda18250_pll_calc(struct dvb_frontend *fe, u8 
*rdiv,
                goto err;
 
        exp = (uval & 0x70) >> 4;
-       if (exp > 5)
-               exp = 0;
+       if (exp == 0 || exp > 5)
+               exp = 1;
        lopd = 1 << (exp - 1);
        scale = uval & 0x0f;
        fvco = lopd * scale * ((c->frequency / 1000) + dev->if_frequency);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to