On Thu Apr 9 15:49:44 2026 +0200, Greg Kroah-Hartman wrote:
> cp_read() returns the negative errno from regmap_read() on I2C failure.
> adv76xx_log_status() shifts the result right by 4 and uses it directly
> to index csc_coeff_sel_rb[16] causing the right shift of a negative
> number to result in -1, reading a negative place in the array.
> 
> Commit 8163419e3e05 ("media: adv7842: Avoid possible out-of-bounds
> array accesses in adv7842_cp_log_status()") fixed the identical pattern
> in the adv7842, so do the same thing here.
> 
> Fixes: 54450f591c99 ("[media] adv7604: driver for the Analog Devices ADV7604 
> video decoder")
> Cc: [email protected]
> Assisted-by: gregkh_clanker_t1000
> Signed-off-by: Greg Kroah-Hartman <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/i2c/adv7604.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

---

diff --git a/drivers/media/i2c/adv7604.c b/drivers/media/i2c/adv7604.c
index ac9c69ce438f..231edd3797ab 100644
--- a/drivers/media/i2c/adv7604.c
+++ b/drivers/media/i2c/adv7604.c
@@ -2641,8 +2641,9 @@ static int adv76xx_log_status(struct v4l2_subdev *sd)
                                        "(16-235)" : "(0-255)",
                                (reg_io_0x02 & 0x08) ? "enabled" : "disabled");
        }
+       ret = cp_read(sd, info->cp_csc) >> 4;
        v4l2_info(sd, "Color space conversion: %s\n",
-                       csc_coeff_sel_rb[cp_read(sd, info->cp_csc) >> 4]);
+                       ret < 0 ? "" : csc_coeff_sel_rb[ret]);
 
        if (!is_digital_input(sd))
                return 0;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to