On Sat Sep 26 15:49:29 2026 +1000, Weigang He wrote:
> fintek_get_rx_ir_data() drains the CIR RX FIFO into fintek->buf[], which
> holds RX_BUF_LEN (32) bytes, for as long as CIR_STATUS reports pending
> RX data:
>
> do {
> sample = fintek_cir_reg_read(fintek, CIR_RX_DATA);
> ...
> fintek->buf[fintek->pkts] = sample;
> fintek->pkts++;
> ...
> } while (status & rx_irqs);
>
> Nothing bounds fintek->pkts. If the hardware reports data for more than
> RX_BUF_LEN reads in one interrupt, the loop writes past the end of
> buf[], starting with the pkts counter that follows it in struct
> fintek_dev.
>
> Hand a full buffer to fintek_process_rx_ir_data(), which parses the
> samples and resets fintek->pkts, before storing the next sample. This
> keeps the parser state consistent and drops no samples. The loop still
> relies on the status register to terminate.
>
> The driver does not document the hardware FIFO depth, so it is not
> known whether a working device can trigger this.
>
> Found by static analysis tool CodeQL.
>
> Fixes: 9bdc79ea07d9 ("[media] fintek-cir: new driver for Fintek LPC SuperIO
> CIR function")
> Cc: [email protected]
> Assisted-by: LLM codeql
> Signed-off-by: Weigang He <[email protected]>
> Signed-off-by: Sean Young <[email protected]>
Patch committed.
Thanks,
Sean Young
drivers/media/rc/fintek-cir.c | 4 ++++
1 file changed, 4 insertions(+)
---
diff --git a/drivers/media/rc/fintek-cir.c b/drivers/media/rc/fintek-cir.c
index d4368181fef6..7b6931f40a5b 100644
--- a/drivers/media/rc/fintek-cir.c
+++ b/drivers/media/rc/fintek-cir.c
@@ -328,6 +328,10 @@ static void fintek_get_rx_ir_data(struct fintek_dev
*fintek, u8 rx_irqs)
sample = fintek_cir_reg_read(fintek, CIR_RX_DATA);
fit_dbg("%s: sample: 0x%02x", __func__, sample);
+ /* Process a full buffer before storing the next sample. */
+ if (fintek->pkts >= RX_BUF_LEN)
+ fintek_process_rx_ir_data(fintek);
+
fintek->buf[fintek->pkts] = sample;
fintek->pkts++;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]