On Thu Apr 9 15:49:44 2026 +0200, Greg Kroah-Hartman wrote:
> cp_read() returns the negative errno from regmap_read() on I2C failure.
> adv76xx_log_status() shifts the result right by 4 and uses it directly
> to index csc_coeff_sel_rb[16] causing the right shift of a negative
> number to result in -1, reading a negative place in the array.
>
> Commit 8163419e3e05 ("media: adv7842: Avoid possible out-of-bounds
> array accesses in adv7842_cp_log_status()") fixed the identical pattern
> in the adv7842, so do the same thing here.
>
> Fixes: 54450f591c99 ("[media] adv7604: driver for the Analog Devices ADV7604
> video decoder")
> Cc: [email protected]
> Assisted-by: gregkh_clanker_t1000
> Signed-off-by: Greg Kroah-Hartman <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/i2c/adv7604.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
---
diff --git a/drivers/media/i2c/adv7604.c b/drivers/media/i2c/adv7604.c
index ac9c69ce438f..231edd3797ab 100644
--- a/drivers/media/i2c/adv7604.c
+++ b/drivers/media/i2c/adv7604.c
@@ -2641,8 +2641,9 @@ static int adv76xx_log_status(struct v4l2_subdev *sd)
"(16-235)" : "(0-255)",
(reg_io_0x02 & 0x08) ? "enabled" : "disabled");
}
+ ret = cp_read(sd, info->cp_csc) >> 4;
v4l2_info(sd, "Color space conversion: %s\n",
- csc_coeff_sel_rb[cp_read(sd, info->cp_csc) >> 4]);
+ ret < 0 ? "" : csc_coeff_sel_rb[ret]);
if (!is_digital_input(sd))
return 0;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]