[PATCH] cpufreq: imx6q: fix out-of-bounds write when probed more than once
Viresh Kumar
viresh.kumar at linaro.org
Wed Aug 5 23:07:38 PDT 2026
On 06-08-26, 07:02, Karl Mehltretter wrote:
> imx6_soc_volt is allocated fresh on every probe, sized to the number of
> ARM OPPs:
>
> imx6_soc_volt = devm_kcalloc(cpu_dev, num, sizeof(*imx6_soc_volt),
> GFP_KERNEL);
>
> but it is filled through soc_opp_count, which has static storage and is
> never reset. A second bind after an unbind keeps indexing from where the
> first one stopped, and writes past the end of the new array.
>
> Unbinding and rebinding the driver on qemu's mcimx6ul-evk, under KASAN:
>
> BUG: KASAN: slab-out-of-bounds in imx6q_cpufreq_probe+0x3b0/0xa34
> Write of size 4 at addr c5e90480 by task binder/73
> imx6q_cpufreq_probe from platform_probe+0x88/0xe4
> platform_probe from really_probe+0x108/0x384
> bind_store from kernfs_fop_write_iter+0x1b4/0x28c
>
> The write lands one u32 past the end of the allocation.
>
> soc_opp_count is only read a few lines below the loop that fills it, so it
> never needed static storage. Make it a local.
>
> Fixes: b4573d1d657a ("cpufreq: imx6q: correct VDDSOC/PU voltage scaling when cpufreq is changed")
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: Karl Mehltretter <kmehltretter at gmail.com>
> ---
> drivers/cpufreq/imx6q-cpufreq.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
Applied. Thanks.
--
viresh
More information about the linux-arm-kernel
mailing list