[PATCH] cpufreq: imx6q: fix out-of-bounds write when probed more than once

Viresh Kumar viresh.kumar at linaro.org
Wed Aug 5 23:07:38 PDT 2026


On 06-08-26, 07:02, Karl Mehltretter wrote:
> imx6_soc_volt is allocated fresh on every probe, sized to the number of
> ARM OPPs:
> 
> 	imx6_soc_volt = devm_kcalloc(cpu_dev, num, sizeof(*imx6_soc_volt),
> 				     GFP_KERNEL);
> 
> but it is filled through soc_opp_count, which has static storage and is
> never reset. A second bind after an unbind keeps indexing from where the
> first one stopped, and writes past the end of the new array.
> 
> Unbinding and rebinding the driver on qemu's mcimx6ul-evk, under KASAN:
> 
>   BUG: KASAN: slab-out-of-bounds in imx6q_cpufreq_probe+0x3b0/0xa34
>   Write of size 4 at addr c5e90480 by task binder/73
>    imx6q_cpufreq_probe from platform_probe+0x88/0xe4
>    platform_probe from really_probe+0x108/0x384
>    bind_store from kernfs_fop_write_iter+0x1b4/0x28c
> 
> The write lands one u32 past the end of the allocation.
> 
> soc_opp_count is only read a few lines below the loop that fills it, so it
> never needed static storage. Make it a local.
> 
> Fixes: b4573d1d657a ("cpufreq: imx6q: correct VDDSOC/PU voltage scaling when cpufreq is changed")
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: Karl Mehltretter <kmehltretter at gmail.com>
> ---
>  drivers/cpufreq/imx6q-cpufreq.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

Applied. Thanks.

-- 
viresh



More information about the linux-arm-kernel mailing list